Back to skill

Security audit

Elevenlabs Tts

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed ElevenLabs voiceover helper that sends the job script to ElevenLabs, saves audio, and rewrites subtitle timing files in the job folder.

Install only if you are comfortable sending the job's TTS script to ElevenLabs using your API key. This skill intentionally mutates input.json by replacing predicted subtitles, so keep an original copy if you need the pre-run timings.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.