Back to skill

Security audit

AI Image Generation — Pro Pack on RunComfy

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed RunComfy image-generation helper that uses the RunComfy CLI and stored auth as expected for its purpose.

Before installing, make sure you are comfortable with RunComfy CLI requests using your RunComfy account and credits. For ambiguous image requests, confirm the intended model, inputs, output directory, and whether web grounding or reference URLs should be used.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill advertises very broad natural-language triggers such as "generate image", "make a picture", and "AI image", which can cause the agent to invoke the skill in contexts the user did not clearly intend. Because this skill performs networked CLI actions and may consume API credits or process user-provided assets, accidental activation has real cost and privacy implications.

Session Persistence

Medium
Category
Rogue Agent
Content
<model>/text-to-image` or `/edit` through the local RunComfy CLI.
  Triggers on "generate image", "make a picture", "text to image",
  "AI image", "make an image of …", "image to image", "i2i", or any
  explicit ask to create or restyle an image with RunComfy.
emoji: "🎨"
homepage: https://www.runcomfy.com
license: MIT
Confidence
74% confidence
Finding
create or restyle an image with RunComfy. emoji: "🎨" homepage: https://www.runcomfy.com license: MIT clawdis: requires: bins: - runcomfy env: - RUNCOMFY_TOKEN config: -

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.