Back to skill

Security audit

⏭️ Video Extend — Pro Pack on RunComfy

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward RunComfy helper for extending user-selected videos, with disclosed API, token, and file-output behavior.

Install only if you trust the RunComfy CLI and intend to send the selected video URL and prompt to RunComfy for video generation. Protect your RunComfy token, confirm expected credit cost before running chained extensions, and avoid submitting sensitive videos unless you are comfortable with that external processing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

49/49 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.