skills/gencraft-labs/skills/lipsync/Gen Agent Trust Hub

lipsync

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of the runcomfy command-line tool to drive lip-syncing models.
  • [EXTERNAL_DOWNLOADS]: The documentation instructs the user to install the @runcomfy/cli package from the public NPM registry.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content by ingesting video and audio URLs, which creates a potential surface for indirect prompt injection.
  • Ingestion points: The video_url and audio_url parameters in the runcomfy run commands found in SKILL.md.
  • Boundary markers: The skill documentation specifies that these inputs are passed as a JSON string to the --input argument to prevent shell expansion.
  • Capability inventory: The skill's capabilities are limited to executing the runcomfy tool as specified in the allowed-tools frontmatter in SKILL.md.
  • Sanitization: The skill documentation claims the CLI does not perform shell expansion on the provided JSON input string.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 12:39 PM