relight
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill specifies the installation of the
@runcomfy/clipackage from the NPM registry. This package is owned by the vendor (runcomfy-com) and is essential for the skill's operations. - [COMMAND_EXECUTION]: The skill utilizes
Bash(runcomfy *)to execute CLI commands for logging in and running relighting models. These commands are restricted to the vendor's toolset. - [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it processes external images.
-
- Ingestion points: The skill takes image URLs as input in SKILL.md.
-
- Boundary markers: The skill includes documentation advising agents to only use user-provided URLs, though no structural boundaries are present in the prompt instructions.
-
- Capability inventory: Commands in SKILL.md use the
runcomfyCLI to perform network-based image transformations.
- Capability inventory: Commands in SKILL.md use the
-
- Sanitization: Inputs are encapsulated in JSON within the CLI call to mitigate shell injection, though the model remains vulnerable to instructions embedded in input assets.
Audit Metadata