wan-3-0-prime-reference-to-video
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
runcomfyCLI (vianpxor local installation) to invoke video generation tasks. These commands are parameter-controlled and follow the documented schema for the RunComfy Model API. - [EXTERNAL_DOWNLOADS]: The skill downloads generated video assets from RunComfy's official infrastructure (
*.runcomfy.netand*.runcomfy.com). These are recognized as well-known service domains for this toolset and are considered safe. - [INDIRECT_PROMPT_INJECTION]: The skill documentation explicitly identifies the risk of prompt injection via reference media (images, video, audio) and instructs the agent to treat all such data as untrusted generation inputs rather than instructions. This follows security best practices for multimodal agent skills.
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data exfiltration were detected. The skill uses standard authentication via tokens or device flows.
Audit Metadata