Back to skill

Security audit

Lipsync — Pro Pack on RunComfy

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed RunComfy lip-sync helper, with expected external media processing and clear consent guidance.

Install only if you are comfortable using RunComfy's cloud service for the media you provide. Confirm rights and consent for both the face and voice before use, especially for real people, and avoid sending private or sensitive media URLs unless that external processing is acceptable.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list includes broad natural-language phrases such as 'dub video', 'voiceover sync', and 'make this video speak', which can cause the skill to activate outside narrowly intended lipsync requests. Unintended invocation is risky here because the skill can process sensitive media and route it to external RunComfy endpoints, creating privacy, consent, and misuse exposure if activated on the wrong user intent.

Static analysis

No suspicious patterns detected.