Back to skill

Security audit

๐ŸŽต ElevenLabs AI Music Generation โ€” Pro Pack on RunComfy

Security checks across malware telemetry and agentic risk

Overview

This skill transparently uses the RunComfy CLI to generate music through an external paid model API, with the main caution being cost, token use, and prompt privacy.

Install only if you trust the RunComfy CLI and intend to use a RunComfy account for paid music generation. Review duration before running long generations, keep RUNCOMFY_TOKEN private, and avoid submitting confidential lyrics, brand material, or unreleased creative work unless you are comfortable sending it to RunComfy/ElevenLabs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list is broad and includes generic phrases such as 'compose', 'generate music', and 'background music', which can plausibly appear in ordinary conversation and cause unintended skill activation. In this skill, unintended invocation can trigger a paid external API call through the local CLI, creating avoidable cost, privacy exposure of user prompts to a third party, and surprising side effects.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.