lipsync
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends the installation of the '@runcomfy/cli' Node.js package, which is the official tool provided by the vendor.
- [COMMAND_EXECUTION]: The skill uses the 'runcomfy' CLI to process lip-sync tasks. This usage is restricted to the specific vendor tool by the platform's 'allowed-tools' configuration.
- [PROMPT_INJECTION]: The skill ingests external media URLs, which represents a surface for indirect prompt injection. The documentation correctly identifies this risk and places the responsibility for input vetting on the operator.
- [SAFE]: Documentation includes security-conscious guidance, such as restricting access to local credential files and advising against piping remote scripts into the shell.
Audit Metadata