Back to skill

Security audit

ComfyUI Client

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its ComfyUI image/video purpose, but a malicious configured ComfyUI server could cause it to write downloaded outputs outside the intended folder.

Review before installing. Use only a trusted local ComfyUI endpoint if possible, avoid pointing --server or COMFYUI_SERVER_URL at an untrusted host, and be aware the current downloader does not safely constrain server-provided output filenames to the declared output directory.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/comfyUIClient.js:982
Finding

Arbitrary File Write Through Unvalidated ComfyUI Output Filename

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 24)May include surrounding context.

可选:复制环境变量模板并修改服务端地址(与命令行 --server 等价)。

bash
cp .env.example .env   # Windows 可复制 .env.example 并重命名为 .env

使用示例

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
**脚本:** `scripts/comfyUIClient.js` - ComfyUI 工作流调用主脚本

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
**脚本:** `scripts/comfyUIClient.js` - ComfyUI 工作流调用主脚本

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
**脚本:** `scripts/comfyUIClient.js` - ComfyUI 工作流调用主脚本

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
**脚本:** `scripts/comfyUIClient.js` - ComfyUI 工作流调用主脚本

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/comfyUIClient.js (reported line 45)May include surrounding context.

js
}

const projectRoot = resolveProjectRoot(__dirname);
require('dotenv').config({ path: path.join(projectRoot, '.env') });
global.rootDir = projectRoot;

class ComfyUIClient {

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/comfyUIClient.js (reported line 1044)May include surrounding context.

js
if (hasFiles) {
                            console.log('✅ 检测到输出文件,任务完成');
                            return promptData;
                        }
                    }

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/comfyUIClient.js (reported line 1051)May include surrounding context.

js
if (hasFiles) {
                            console.log('✅ 检测到输出文件,任务完成');
                            return promptData;
                        }
                    }

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is written as a directive in Chinese ('此技能应在...时使用') and the entire skill documentation is presented only in Chinese, which implies a fixed language/locale for operation without offering the user a language choice. This matches the policy category for language or locale constraints that are not opt-in or explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code file contains user-facing documentation, help text, logs, and error messages entirely in Chinese, which imposes a specific language on users. The policy allows locale constraints only when users are given an opt-in choice or the restriction is clearly justified, neither of which is present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The markdown states that generated images or videos are polled and saved locally, which is a data-affecting behavior covered by the warning requirement for markdown files. Although the purpose of the skill is explained, there is no explicit caution or user-facing warning that running the skill will create local output files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language note directs users to a zh-CN installation/update page, which imposes a specific locale in user-facing guidance without opt-in or justification. This can conflict with language/locale policy expectations when the rest of the workflow is otherwise general-purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON workflow includes a SaveImage node that writes output images to local storage, but the surrounding notes and descriptions in the file do not warn the user that running the workflow will create files on disk. For a workflow/config file with embedded markdown guidance, this is a user-impacting write operation that lacks visible disclosure in the file text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

At L1, the embedded prompt text includes 'a latina model' in the default workflow configuration. This hard-codes a demographic attribute into the skill's natural-language behavior rather than leaving such locale/cultural or user-preference-sensitive output to user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON workflow contains multiple user-facing strings in Chinese (for node labels and one prompt) and English (notes and another prompt), but nowhere indicates that language is selectable or that the workflow is intended for a specific locale. That creates a natural-language locale inconsistency that may force some users into a language they did not opt into.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This JSON workflow includes user-facing natural-language text in both Chinese and English, such as prompt text, node labels, and notes, but does not indicate that the user can choose their preferred language or locale. That can create a language/locale policy issue if the skill experience is effectively fixed or inconsistent without explicit user opt-in.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency uses a caret version range (^16.4.7), which permits automatic installation of future compatible releases rather than an exact audited version. This can introduce supply-chain risk if a later published version is compromised or causes unexpected behavior, although the risk is limited here because the package is a common, low-risk utility and this file alone does not show any dangerous install hooks or broad dependency set.

Content

Scanner excerpt · package.json (reported line 14)May include surrounding context.

json
"comfyui": "node scripts/comfyUIClient.js"
  },
  "dependencies": {
    "dotenv": "^16.4.7"
  }
}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

This markdown file presents all instructions and path guidance exclusively in Chinese, and nowhere indicates that the skill is region-specific or that users can choose another language. That can violate a language/locale policy when users are not given an opt-in or alternative.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.