Back to skill

Security audit

Image Edit — Pro Pack on RunComfy

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed RunComfy image-editing router that sends user-provided image URLs and prompts to RunComfy for editing.

Install this only if you are comfortable sending image URLs, masks, and edit prompts to RunComfy; avoid using private or sensitive images unless their exposure to that service is acceptable.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger text includes a catch-all phrase such as 'any explicit ask to edit an image,' which makes activation overly broad and can cause the skill to run in contexts the user did not specifically target. In an agent setting, broad routing increases the chance of unintended tool invocation, accidental exfiltration of user-supplied image URLs to a third-party service, and confusion with other more appropriate skills.

Static analysis

No suspicious patterns detected.