Back to skill

Security audit

ControlNet & Pose — Pro Pack on RunComfy

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed RunComfy integration for pose-conditioned image and video generation, with no hidden or unrelated behavior found.

Install only if you are comfortable using RunComfy as an external cloud service for prompts and media URLs. Confirm the agent is using assets you intentionally provided, and keep the RunComfy token scoped and removable from ~/.config/runcomfy or the RUNCOMFY_TOKEN environment variable.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger text includes a broad fallback phrase: it activates on 'any explicit ask to condition generation on a pose / skeleton / motion / depth / canny reference.' That can cause over-triggering on ordinary multimedia requests that mention pose, motion, depth, or reference images, leading the agent to invoke this skill unexpectedly and potentially send user-provided media URLs or prompts to an external service without sufficiently specific intent.

Static analysis

No suspicious patterns detected.