runway-dev-models

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill incorporates strong security practices for secret management. It explicitly instructs the agent to avoid printing the RUNWAYML_API_SECRET and to keep it within server-side boundaries, preventing exposure to client-side bundles.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external media inputs such as HTTPS URLs and data URIs. It identifies the attack surface where untrusted data enters the agent context (SKILL.md, media input) and mitigates risks by advising against accepting arbitrary remote URLs, instead recommending allowlisted origins or ephemeral uploads.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation and setup guides hosted on the official Runway ML domain (runwayml.com). These are recognized as legitimate vendor resources and do not represent a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 07:15 PM
Security Audit — agent-trust-hub — runway-dev-models