runcomfy-cli

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the runcomfy CLI tool through the Bash tool to perform operations such as running AI models, authenticating users, and checking job status.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a vulnerability surface where the AI agent processes data from external sources (images, videos, or web search results) that could contain malicious instructions.
  • Ingestion points: Untrusted asset URLs or search results provided via the --input JSON parameter in SKILL.md.
  • Boundary markers: The skill uses structured JSON for inputs to separate user prompts from control parameters.
  • Capability inventory: The skill is restricted to the runcomfy binary via the allowed-tools configuration.
  • Sanitization: The instructions state that the CLI transmits JSON directly over HTTPS without shell expansion of prompt content.
  • [EXTERNAL_DOWNLOADS]: The CLI fetches generated model outputs from official service domains, including *.runcomfy.net and *.runcomfy.com.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 12:39 PM