Back to skill

Security audit

Kling 3.0 — Pro Pack on RunComfy

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed RunComfy video-generation wrapper, with expected third-party API use and token handling for its stated purpose.

Install only if you are comfortable using RunComfy for video generation, sending prompts and public image URLs to RunComfy, and storing or providing a RunComfy token. Confirm tier, duration, audio, and output directory before running because generations can cost money and produce large files.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger text includes broad activation language such as matching generic mentions and 'any explicit ask to generate or animate with Kling 3.0,' which can cause the skill to run in situations the user did not clearly intend. In this context, unintended activation can lead to third-party API calls, token use, and billable video-generation jobs, so the issue is operationally and financially meaningful even without code execution.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill description does not clearly warn users that prompts and image URLs are sent to RunComfy, a third-party service. Because this skill handles potentially sensitive creative prompts and externally hosted reference images, missing disclosure increases the risk of unintentional data sharing and privacy violations.

Static analysis

No suspicious patterns detected.