skills/doany-ai/skills/lipsync/Gen Agent Trust Hub

lipsync

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a scoped execution environment restricted to the runcomfy command via Bash(runcomfy *), preventing arbitrary shell access.
  • [EXTERNAL_DOWNLOADS]: Recommends the installation of the @runcomfy/cli package from the official npm registry, which is the standard distribution channel for the vendor's tooling.
  • [DATA_EXFILTRATION]: Describes secure storage of API tokens in ~/.config/runcomfy/token.json with appropriate file permissions (mode 0600) and supports environment variable usage for CI environments.
  • [SAFE]: The skill explicitly includes a 'Security & Privacy' section that warns against dangerous practices like piping remote scripts into shells and addresses the dual-use nature of synthetic media.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 02:23 PM