Back to skill

Security audit

OpenClaw ComfyUI

Security checks for vulnerabilities and agentic risk

Overview

This ComfyUI skill has a coherent image-generation purpose, but its remote HTTP client can write server-controlled files locally without safe path checks.

Review this skill before installing. Use it only with a trusted ComfyUI server, avoid sending private media unless you accept that it will leave the local workspace, and fix or constrain the download path handling before using it against any remote or shared endpoint.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
comfy_client.py:60
Finding

Server-Controlled Filename Permits Arbitrary File Overwrite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
comfy_client.py:29
Finding

ComfyUI Traffic and User Assets Are Transmitted over Unauthenticated Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
comfy_client.py:115
Finding

Unbounded Network Requests, Downloads, and Polling Enable Resource Exhaustion

Content
View full analysis
Remediation
View remediation
MAX_DOWNLOAD: raise ValueError("Download exceeds permitted size") output.write(chunk) ``` ]]>

T08 · Insecure Dependencies

Note
Location
README.md:21
Finding

Third-Party Dependency Is Installed Without Version or Hash Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly advertises automatic upload of input images to a remote ComfyUI host and automatic download of generated results, but it does not warn users about data leaving the local machine, being stored on a remote system, or being written back into the local workspace. In an agent skill context, this omission is security-relevant because users may invoke the skill on sensitive local files without understanding the transfer and filesystem side effects.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documentation explicitly encourages sending generated images through external messaging plugins or opening them locally, which extends behavior beyond basic ComfyUI control and can expose generated or edited content to unintended destinations. In this context, the issue is made more dangerous because image workflows may process sensitive user-provided inputs, and the documentation gives no approval, destination validation, or privacy safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation advises direct delivery of generated images via messaging plugins or local file openers without warning about disclosure risks, which can lead to unintended sharing of sensitive generated or edited images. This is especially relevant for an image-editing skill that may handle private user assets, making silent exfiltration or oversharing more plausible in normal use.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code derives the network destination from a writable local documentation/config file and then uses that value to send prompts, uploads, and downloads over HTTP. If TOOLS.md is modified by another process or attacker, the client can be redirected to an unintended service, causing data exfiltration of prompts and uploaded files or retrieval of untrusted content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The upload_file function reads a local file and transmits it to the ComfyUI server via requests.post, but the code provides no confirmation prompt or user-facing disclosure at the point of transmission. While uploading may be part of the skill's purpose, this file itself does not visibly warn the user that local file contents are being sent to a service endpoint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The client writes server-controlled content to disk using a server-supplied filename joined directly into the output directory. A malicious or redirected server can return filenames containing path traversal sequences or overwrite-sensitive names, causing files to be written outside the intended directory or clobbering existing files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON workflow contains natural-language prompt content in multiple languages on L145, but there is no indication that the user opted into a specific language or multilingual behavior. Under the policy rule for language/locale constraints, embedding fixed language content without explanation can create an undocumented language behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.