video-edit
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes the @runcomfy/cli via runcomfy run commands to perform video processing tasks. It passes user-provided data into these commands via a structured JSON input string.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the user (prompts) and external sources (video/image URLs) and passes them to remote AI models. This creates a surface for indirect prompt injection where malicious content in a processed video or image could influence the model's behavior. The skill documentation explicitly acknowledges this risk. * Ingestion points: prompt, video, image, and reference_image fields in SKILL.md. * Boundary markers: The CLI uses a JSON structure for input, providing some separation. * Capability inventory: File writing (--output-dir), command execution (runcomfy), and network operations to runcomfy.net. * Sanitization: The skill notes that external URLs should be treated as untrusted and mentions that image-based injection is a risk.
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @runcomfy/cli package from the npm registry and uses the runcomfy command to interact with remote services. It also downloads generated video files from runcomfy.net or runcomfy.com domains to a local output directory.
Audit Metadata