Back to skill

Security audit

AI Music — Pro Pack on RunComfy

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed RunComfy music-generation helper with expected CLI, token, network, and output-file behavior for that purpose.

Install only if you intend to use RunComfy for cloud music generation and are comfortable with API-token use and per-generation costs. Confirm before running generation from ambiguous music requests, keep RUNCOMFY_TOKEN out of logs and prompts, and only submit audio URLs or lyrics you have rights to use.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes many broad, everyday phrases such as 'background music', 'compose', and 'theme music', which can cause the skill to activate in contexts where the user did not intend to invoke this specific tool. Because the skill can initiate external CLI usage tied to an authenticated third-party service, accidental invocation can lead to unintended network actions, cost-incurring jobs, or confusing tool routing.

Static analysis

No suspicious patterns detected.