flux-2-klein

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the @runcomfy/cli package from the official npm registry. This is a legitimate dependency for the vendor's own platform.
  • [COMMAND_EXECUTION]: The skill documents the use of the runcomfy run command to submit image generation requests. The documentation includes security details explaining that the CLI transmits JSON bodies directly to the API without shell-expansion of user prompts, mitigating common injection risks.
  • [SAFE]: All network operations and API endpoints (model-api.runcomfy.net, *.runcomfy.com) are owned and operated by the skill's author (runcomfy-com), representing standard functionality for the service.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 02:02 PM