skills/genmedia-labs/skills/relight/Gen Agent Trust Hub

relight

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @runcomfy/cli package from the NPM registry using npm i -g @runcomfy/cli or npx. This is the primary tool for interacting with the service.\n- [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute runcomfy commands for authentication and image processing as defined in the allowed-tools metadata.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the ingestion of untrusted external content.\n
  • Ingestion points: The image and image_urls parameters within the JSON input for the runcomfy run command in SKILL.md.\n
  • Boundary markers: Absent. There are no explicit delimiters or instructions to ignore embedded content within the processed image URLs or prompts.\n
  • Capability inventory: The skill has the capability to execute shell commands via Bash(runcomfy *) across its operational flow.\n
  • Sanitization: Absent. The skill relies on the CLI tool's handling of input and does not implement independent sanitization or validation of the external assets or prompt strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 10:56 AM
Security Audit — agent-trust-hub — relight