gpt-image-2
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes the
runcomfyCLI tool to perform image processing tasks. This is a core part of the skill's functionality and is used to transmit structured JSON payloads to the service's API. - [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@runcomfy/clipackage from the official NPM registry and fetches generated image files from authorized*.runcomfy.netor*.runcomfy.comdomains. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection as it processes external image URLs and user-provided prompts.
- Ingestion points: User-provided
promptandimagesURLs inSKILL.mdinstructions. - Boundary markers: The documentation notes that the CLI avoids shell expansion and transmits data via JSON, reducing the risk of command injection from prompt content.
- Capability inventory: The skill uses subprocess calls to the
runcomfyCLI and performs network operations via the CLI to the RunComfy API. - Sanitization: Content is encapsulated in JSON strings before being passed to the CLI.
- [CREDENTIALS_UNSAFE]: The documentation discusses the management of API tokens for the RunComfy service, recommending the use of environment variables or owner-restricted configuration files (
~/.config/runcomfy/token.json), which follows standard security practices for API integrations.
Audit Metadata