gpt-image-2

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes the runcomfy CLI tool to perform image processing tasks. This is a core part of the skill's functionality and is used to transmit structured JSON payloads to the service's API.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @runcomfy/cli package from the official NPM registry and fetches generated image files from authorized *.runcomfy.net or *.runcomfy.com domains.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection as it processes external image URLs and user-provided prompts.
  • Ingestion points: User-provided prompt and images URLs in SKILL.md instructions.
  • Boundary markers: The documentation notes that the CLI avoids shell expansion and transmits data via JSON, reducing the risk of command injection from prompt content.
  • Capability inventory: The skill uses subprocess calls to the runcomfy CLI and performs network operations via the CLI to the RunComfy API.
  • Sanitization: Content is encapsulated in JSON strings before being passed to the CLI.
  • [CREDENTIALS_UNSAFE]: The documentation discusses the management of API tokens for the RunComfy service, recommending the use of environment variables or owner-restricted configuration files (~/.config/runcomfy/token.json), which follows standard security practices for API integrations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:34 PM
Security Audit — agent-trust-hub — gpt-image-2