flux-kontext

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute the runcomfy CLI tool to perform image edits. This involves running commands like runcomfy run blackforestlabs/flux-1-kontext/pro/edit with JSON-formatted input.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of @runcomfy/cli from the npm registry, which is a well-known service for Node.js packages.
  • [DATA_EXPOSURE]: The skill documents the use of RUNCOMFY_TOKEN for authentication and notes that the CLI stores tokens in ~/.config/runcomfy/token.json with restricted permissions (0600), which is a standard and safe credential management practice.
  • [SAFE]: The security section of the skill explicitly addresses input boundaries, third-party content risks (image-based prompt injection), and outbound endpoint whitelisting, demonstrating good security documentation practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 10:56 AM
Security Audit — agent-trust-hub — flux-kontext