ai-music
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documents the installation of the
@runcomfy/clipackage and theruncomfy-agent-skillsfrom theagentspace-sorepository. These are legitimate vendor resources used for the skill's primary purpose. - [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface when processing external audio files via URLs for music editing features. It includes explicit security warnings and guidance for the agent to mitigate this risk by only using user-provided URLs and monitoring for output divergence.
- [SAFE]: The documentation mentions the storage location of API tokens at
~/.config/runcomfy/token.jsonas part of its security and privacy guidance, providing transparency on how the underlying CLI manages credentials and instructing the agent not to access or exfiltrate them.
Audit Metadata