lipsync
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the execution of the
runcomfycommand-line tool to drive lip-syncing models. - [EXTERNAL_DOWNLOADS]: The documentation instructs the user to install the
@runcomfy/clipackage from the public NPM registry. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content by ingesting video and audio URLs, which creates a potential surface for indirect prompt injection.
- Ingestion points: The
video_urlandaudio_urlparameters in theruncomfy runcommands found inSKILL.md. - Boundary markers: The skill documentation specifies that these inputs are passed as a JSON string to the
--inputargument to prevent shell expansion. - Capability inventory: The skill's capabilities are limited to executing the
runcomfytool as specified in theallowed-toolsfrontmatter inSKILL.md. - Sanitization: The skill documentation claims the CLI does not perform shell expansion on the provided JSON input string.
Audit Metadata