ai-music

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documents the installation of the @runcomfy/cli package and the runcomfy-agent-skills from the agentspace-so repository. These are legitimate vendor resources used for the skill's primary purpose.
  • [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface when processing external audio files via URLs for music editing features. It includes explicit security warnings and guidance for the agent to mitigate this risk by only using user-provided URLs and monitoring for output divergence.
  • [SAFE]: The documentation mentions the storage location of API tokens at ~/.config/runcomfy/token.json as part of its security and privacy guidance, providing transparency on how the underlying CLI manages credentials and instructing the agent not to access or exfiltrate them.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 04:11 AM
Security Audit — agent-trust-hub — ai-music