Back to skill

Security audit

ElevenLabs AI Music Generation — Pro Pack on RunComfy

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed helper for generating music through RunComfy and does not show hidden or purpose-mismatched behavior.

Install this only if you intend agents to generate music through RunComfy. Review RunComfy pricing and token handling first, and prefer confirming duration and output settings before running paid generations.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list is broad enough to match many ordinary user requests about music, background audio, or composition, which can cause the agent to invoke this skill unexpectedly. Because the skill performs external CLI/API actions that may incur cost and use stored credentials, overbroad activation increases the risk of unintended execution, billing, and data flow to a third-party service.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.