video-extend

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted video URLs which presents an indirect prompt injection surface. Evidence chain: 1) Ingestion point: video_url in SKILL.md. 2) Boundary markers: Arguments are passed via a JSON string to the CLI. 3) Capability inventory: The runcomfy tool performs network operations and local file writes. 4) Sanitization: The CLI is documented to avoid shell expansion of inputs.\n- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill references the installation of @runcomfy/cli from the official NPM registry. This is a vendor-owned resource necessary for the skill's function.\n- [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute the runcomfy CLI, with execution scope limited by the allowed-tools configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 10:57 AM
Security Audit — agent-trust-hub — video-extend