image-to-video
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to invoke the
runcomfycommand-line utility. It uses a structured approach, passing user inputs such as prompts and URLs within a JSON object to the CLI's--inputflag. The documentation notes that this method is intended to prevent shell injection by avoiding direct shell expansion of the prompt content. - [EXTERNAL_DOWNLOADS]: The skill documentation requires the installation of the
@runcomfy/clipackage from the public NPM registry. It also describes the CLI's behavior of downloading generated video files from vendor-specific domains (runcomfy.netandruncomfy.com) to a user-specified output directory. These activities are consistent with the skill's stated purpose of interacting with the RunComfy service. - [INDIRECT_PROMPT_INJECTION]: As the skill is designed to process untrusted user-supplied data—including text prompts and external media URLs—it presents a surface for indirect prompt injection attacks at the model layer.
- Ingestion points: User-provided inputs are accepted for
image_url,video_url,audio_url, andpromptfields as detailed inSKILL.mdroutes. - Boundary markers: The skill uses JSON encapsulation as a boundary between the user-supplied string and the shell command execution.
- Capability inventory: The skill has capabilities for shell command execution (
runcomfy), network access (handled by the CLI), and file system writes (via the--output-dirparameter). - Sanitization: The instructions rely on JSON stringification provided by the agent's execution environment to escape potentially malicious characters before they are passed to the CLI.
Audit Metadata