T09 · Insecure Skill Coding Practices
- Location
comfy_client.py:60- Finding
Server-Controlled Filename Permits Arbitrary File Overwrite
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This ComfyUI skill has a coherent image-generation purpose, but its remote HTTP client can write server-controlled files locally without safe path checks.
Review this skill before installing. Use it only with a trusted ComfyUI server, avoid sending private media unless you accept that it will leave the local workspace, and fix or constrain the download path handling before using it against any remote or shared endpoint.
comfy_client.py:60Server-Controlled Filename Permits Arbitrary File Overwrite
comfy_client.py:29ComfyUI Traffic and User Assets Are Transmitted over Unauthenticated Plaintext HTTP
comfy_client.py:115Unbounded Network Requests, Downloads, and Polling Enable Resource Exhaustion
README.md:21Third-Party Dependency Is Installed Without Version or Hash Pinning
The README explicitly advertises automatic upload of input images to a remote ComfyUI host and automatic download of generated results, but it does not warn users about data leaving the local machine, being stored on a remote system, or being written back into the local workspace. In an agent skill context, this omission is security-relevant because users may invoke the skill on sensitive local files without understanding the transfer and filesystem side effects.
The skill documentation explicitly encourages sending generated images through external messaging plugins or opening them locally, which extends behavior beyond basic ComfyUI control and can expose generated or edited content to unintended destinations. In this context, the issue is made more dangerous because image workflows may process sensitive user-provided inputs, and the documentation gives no approval, destination validation, or privacy safeguards.
The documentation advises direct delivery of generated images via messaging plugins or local file openers without warning about disclosure risks, which can lead to unintended sharing of sensitive generated or edited images. This is especially relevant for an image-editing skill that may handle private user assets, making silent exfiltration or oversharing more plausible in normal use.
The code derives the network destination from a writable local documentation/config file and then uses that value to send prompts, uploads, and downloads over HTTP. If TOOLS.md is modified by another process or attacker, the client can be redirected to an unintended service, causing data exfiltration of prompts and uploaded files or retrieval of untrusted content.
The upload_file function reads a local file and transmits it to the ComfyUI server via requests.post, but the code provides no confirmation prompt or user-facing disclosure at the point of transmission. While uploading may be part of the skill's purpose, this file itself does not visibly warn the user that local file contents are being sent to a service endpoint.
The client writes server-controlled content to disk using a server-supplied filename joined directly into the output directory. A malicious or redirected server can return filenames containing path traversal sequences or overwrite-sensitive names, causing files to be written outside the intended directory or clobbering existing files.
This JSON workflow contains natural-language prompt content in multiple languages on L145, but there is no indication that the user opted into a specific language or multilingual behavior. Under the policy rule for language/locale constraints, embedding fixed language content without explanation can create an undocumented language behavior.
No suspicious patterns detected.