Back to skill

Security audit

Codex Pet — Pro Pack on RunComfy

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Codex Pet generator that uses RunComfy and ImageMagick to create local pet files, with no hidden or destructive behavior found.

Install this only if you are comfortable sending the chosen public image URL to RunComfy/OpenAI through the RunComfy CLI and writing the generated pet files under your Codex home directory. Review the generated commands before running them, especially PET_NAME, SOURCE_URL, and the destination path.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger text includes a catch-all phrase such as 'any explicit ask to build a custom pet,' which can cause the skill to activate in contexts beyond a narrowly scoped command. Overbroad activation increases the chance of unintended execution of a skill that performs network calls and writes files under the user's home directory.

Vague Triggers

Low
Confidence
83% confidence
Finding
The usage guidance repeats broad trigger examples like '/hatch' and general references to 'spritesheet.webp' without clear boundaries. This can lead to accidental invocation during ordinary discussion, increasing exposure to unnecessary outbound requests and local file creation.

Static analysis

No suspicious patterns detected.