flux-2-klein
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the
@runcomfy/clipackage from the official npm registry. This is a legitimate dependency for the vendor's own platform. - [COMMAND_EXECUTION]: The skill documents the use of the
runcomfy runcommand to submit image generation requests. The documentation includes security details explaining that the CLI transmits JSON bodies directly to the API without shell-expansion of user prompts, mitigating common injection risks. - [SAFE]: All network operations and API endpoints (
model-api.runcomfy.net,*.runcomfy.com) are owned and operated by the skill's author (runcomfy-com), representing standard functionality for the service.
Audit Metadata