ai-avatar-video

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the @runcomfy/cli package for installation via the npm registry. This is a legitimate vendor resource provided by the skill author for accessing their API.
  • [COMMAND_EXECUTION]: Usage is restricted to the runcomfy CLI tool as defined in the allowed-tools metadata. The skill provides structured command templates for interacting with specific AI models.
  • [DATA_EXFILTRATION]: Network operations are directed exclusively to the vendor's official domains (runcomfy.com and runcomfy.net) to facilitate model execution and asset retrieval.
  • [SAFE]: The skill includes a proactive 'Security & Privacy' section that educates the agent on mitigating indirect prompt injection and emphasizes the importance of user consent for identity-based video generation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 01:21 PM