rw-integrate-characters
Pass
Audited by Gen Agent Trust Hub on Apr 17, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download a starter project from Runway's official GitHub repository using the
degittool. - [EXTERNAL_DOWNLOADS]: Recommends installing official SDKs (
@runwayml/sdkand@runwayml/avatars-react) from the vendor's verified package registry. - [DATA_EXPOSURE_AND_EXFILTRATION]: Explicitly warns users to keep API keys on the server-side to prevent exposure to the client-side environment.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided
avatarIdstrings in server-side API routes to initiate sessions. This is a standard integration pattern with no suspicious behavior or lack of boundary markers in the provided logic.
Audit Metadata