animate-image

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch media from external URLs provided by users or specified in examples (e.g., example.com, vm.runware.ai). The domain vm.runware.ai is the official infrastructure of the skill author.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it processes user-provided descriptions and images to generate video prompts.
  • Ingestion points: SKILL.md (user-supplied motion descriptions and image URLs).
  • Boundary markers: The skill uses structured JSON objects for tool parameters, though it lacks explicit instructions to ignore embedded commands within user-provided data.
  • Capability inventory: SKILL.md (uses videoInference and getResponse tools).
  • Sanitization: No explicit sanitization or filtering of user input is described in the prompt templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 04:08 PM
Security Audit — agent-trust-hub — animate-image