rw-integrate-characters

Pass

Audited by Gen Agent Trust Hub on Apr 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download a starter project from Runway's official GitHub repository using the degit tool.
  • [EXTERNAL_DOWNLOADS]: Recommends installing official SDKs (@runwayml/sdk and @runwayml/avatars-react) from the vendor's verified package registry.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: Explicitly warns users to keep API keys on the server-side to prevent exposure to the client-side environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided avatarId strings in server-side API routes to initiate sessions. This is a standard integration pattern with no suspicious behavior or lack of boundary markers in the provided logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 17, 2026, 06:43 AM