T09 · Insecure Skill Coding Practices
- Location
scripts/comfyUIClient.js:982- Finding
Arbitrary File Write Through Unvalidated ComfyUI Output Filename
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its ComfyUI image/video purpose, but a malicious configured ComfyUI server could cause it to write downloaded outputs outside the intended folder.
Review before installing. Use only a trusted local ComfyUI endpoint if possible, avoid pointing --server or COMFYUI_SERVER_URL at an untrusted host, and be aware the current downloader does not safely constrain server-provided output filenames to the declared output directory.
scripts/comfyUIClient.js:982Arbitrary File Write Through Unvalidated ComfyUI Output Filename
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
可选:复制环境变量模板并修改服务端地址(与命令行 --server 等价)。
cp .env.example .env # Windows 可复制 .env.example 并重命名为 .env
Referenced artifact was not completely inspected
**脚本:** `scripts/comfyUIClient.js` - ComfyUI 工作流调用主脚本
Referenced artifact was not completely inspected
**脚本:** `scripts/comfyUIClient.js` - ComfyUI 工作流调用主脚本
Referenced artifact was not completely inspected
**脚本:** `scripts/comfyUIClient.js` - ComfyUI 工作流调用主脚本
Referenced artifact was not completely inspected
**脚本:** `scripts/comfyUIClient.js` - ComfyUI 工作流调用主脚本
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
}
const projectRoot = resolveProjectRoot(__dirname);
require('dotenv').config({ path: path.join(projectRoot, '.env') });
global.rootDir = projectRoot;
class ComfyUIClient {
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
if (hasFiles) {
console.log('✅ 检测到输出文件,任务完成');
return promptData;
}
}
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
if (hasFiles) {
console.log('✅ 检测到输出文件,任务完成');
return promptData;
}
}
Without declared permissions the skill's intent is opaque and cannot be validated.
The manifest description is written as a directive in Chinese ('此技能应在...时使用') and the entire skill documentation is presented only in Chinese, which implies a fixed language/locale for operation without offering the user a language choice. This matches the policy category for language or locale constraints that are not opt-in or explicitly justified.
This code file contains user-facing documentation, help text, logs, and error messages entirely in Chinese, which imposes a specific language on users. The policy allows locale constraints only when users are given an opt-in choice or the restriction is clearly justified, neither of which is present here.
The markdown states that generated images or videos are polled and saved locally, which is a data-affecting behavior covered by the warning requirement for markdown files. Although the purpose of the skill is explained, there is no explicit caution or user-facing warning that running the skill will create local output files.
The natural-language note directs users to a zh-CN installation/update page, which imposes a specific locale in user-facing guidance without opt-in or justification. This can conflict with language/locale policy expectations when the rest of the workflow is otherwise general-purpose.
This JSON workflow includes a SaveImage node that writes output images to local storage, but the surrounding notes and descriptions in the file do not warn the user that running the workflow will create files on disk. For a workflow/config file with embedded markdown guidance, this is a user-impacting write operation that lacks visible disclosure in the file text.
At L1, the embedded prompt text includes 'a latina model' in the default workflow configuration. This hard-codes a demographic attribute into the skill's natural-language behavior rather than leaving such locale/cultural or user-preference-sensitive output to user choice.
This JSON workflow contains multiple user-facing strings in Chinese (for node labels and one prompt) and English (notes and another prompt), but nowhere indicates that language is selectable or that the workflow is intended for a specific locale. That creates a natural-language locale inconsistency that may force some users into a language they did not opt into.
This JSON workflow includes user-facing natural-language text in both Chinese and English, such as prompt text, node labels, and notes, but does not indicate that the user can choose their preferred language or locale. That can create a language/locale policy issue if the skill experience is effectively fixed or inconsistent without explicit user opt-in.
The dependency uses a caret version range (^16.4.7), which permits automatic installation of future compatible releases rather than an exact audited version. This can introduce supply-chain risk if a later published version is compromised or causes unexpected behavior, although the risk is limited here because the package is a common, low-risk utility and this file alone does not show any dangerous install hooks or broad dependency set.
"comfyui": "node scripts/comfyUIClient.js"
},
"dependencies": {
"dotenv": "^16.4.7"
}
}
This markdown file presents all instructions and path guidance exclusively in Chinese, and nowhere indicates that the skill is region-specific or that users can choose another language. That can violate a language/locale policy when users are not given an opt-in or alternative.
No suspicious patterns detected.