use-runway-api
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were identified. The skill's operations are consistent with its stated purpose of interacting with the Runway API using provided vendor scripts.\n- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to fetch and follow instructions from an external documentation file at https://docs.dev.runwayml.com/llms.txt to ensure requests match the current API contract.\n
- Ingestion points: SKILL.md (instructions to fetch and follow llms.txt)\n
- Boundary markers: Absent for the documentation content\n
- Capability inventory: Bash tool (used to execute the runway-api.mjs script for network requests), Read tool\n
- Sanitization: Absent for the retrieved documentation content, though the content is consumed as a technical reference rather than direct executable commands.\n- [EXTERNAL_DOWNLOADS]: The skill facilitates the download of generated assets (images and videos) from Runway's storage infrastructure using signed URLs. These downloads are essential for the skill's media generation purpose and target the vendor's own infrastructure.
Audit Metadata