Security audit
Wan 2.7 — Pro Pack on RunComfy
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed RunComfy video-generation helper that sends user-provided prompts and media URLs to RunComfy to create Wan 2.7 videos.
Install only if you are comfortable using the RunComfy CLI and sending prompts, audio URLs, and referenced media to RunComfy's hosted model service. Keep your RunComfy token private and use `RUNCOMFY_TOKEN` in CI or containers when you do not want a local token file.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
