runway-video

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust approval mechanism for paid API calls requiring an exact SHA-256 digest match of the validated request envelope before execution.
  • [SAFE]: Detailed network security controls are employed, including exact-host DNS allowlisting, rejection of IP literals, and DNS pinning to mitigate SSRF and unauthorized data access.
  • [SAFE]: Media integrity is ensured through mandatory SHA-256 hashing, ffprobe metadata validation, and complete ffmpeg decoding to detect malformed or malicious artifacts.
  • [SAFE]: The implementation uses a local exclusive ledger system to provide idempotency and prevent duplicate billing or race conditions during asynchronous task creation.
  • [SAFE]: External communication is restricted to the official, well-known API endpoints of the service provider.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 01:52 PM
Security Audit — agent-trust-hub — runway-video