Back to skill

Security audit

Flux Kontext Pro — Pro Pack on RunComfy

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed RunComfy image-editing integration with a minor overbroad routing note, not evidence of hidden or malicious behavior.

Install this only if you are comfortable sending the prompt and source image URL to RunComfy. For ambiguous requests using just "kontext," confirm that you really want this RunComfy Flux Kontext model rather than another image or text editing tool.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation criteria are overly broad because they include a generic shorthand ("kontext") and "any explicit ask to edit with this model," which can cause the skill to trigger when the user did not clearly intend this specific tool. In an agent setting, over-triggering can misroute requests, send user-supplied image URLs and prompts to a third-party service, and bypass safer or better-matched editing tools.

Vague Triggers

Low
Confidence
89% confidence
Finding
The instruction to route here whenever the user says "Flux Kontext," "kontext," or "BFL Kontext" forces selection without checking whether the request is actually compatible with this skill's constraints. This increases the chance of incorrect tool invocation, unnecessary third-party data transfer, and failure to apply safer or more appropriate alternatives for text editing, multi-image workflows, or non-image tasks.

Static analysis

No suspicious patterns detected.