wan-3-0-prime-reference-to-video

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the runcomfy CLI (via npx or local installation) to invoke video generation tasks. These commands are parameter-controlled and follow the documented schema for the RunComfy Model API.
  • [EXTERNAL_DOWNLOADS]: The skill downloads generated video assets from RunComfy's official infrastructure (*.runcomfy.net and *.runcomfy.com). These are recognized as well-known service domains for this toolset and are considered safe.
  • [INDIRECT_PROMPT_INJECTION]: The skill documentation explicitly identifies the risk of prompt injection via reference media (images, video, audio) and instructs the agent to treat all such data as untrusted generation inputs rather than instructions. This follows security best practices for multimodal agent skills.
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data exfiltration were detected. The skill uses standard authentication via tokens or device flows.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 03:41 AM
Security Audit — agent-trust-hub — wan-3-0-prime-reference-to-video