Back to skill

Security audit

image-with-comfyui

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed ComfyUI client for generating and editing media; its network and file behavior matches that purpose.

Install only if you control or trust the configured ComfyUI endpoint. Prompts, workflow JSON, source images for edit/video/mesh modes, and any configured bearer API key are sent to that endpoint; prefer localhost or trusted HTTPS servers and avoid sensitive media unless the endpoint and output location are acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (15)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
1. **Never re-read on repeat.** Don't re-read `SKILL.md`, `config.json`, or the script for a known config / repeat / same-model job. Defaults are baked in; `--a

Lp1

High
Category
MCP Least Privilege
Confidence
98% confidence
Finding

The skill performs outbound network access to a user-configurable ComfyUI server, uploads prompts and source images, and downloads generated files. This is a true capability/permission gap because network access materially changes the trust boundary and can exfiltrate sensitive prompts, images, and bearer credentials to remote infrastructure.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
98% confidence
Finding

The skill performs outbound network access to a user-configurable ComfyUI server, uploads prompts and source images, and downloads generated files. This is a true capability/permission gap because network access materially changes the trust boundary and can exfiltrate sensitive prompts, images, and bearer credentials to remote infrastructure.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · image_with_comfyui.py (reported line 652)May include surrounding context.

python
prompt_id = result.get("prompt_id")
    error_msg = result.get("error", {}).get("message", "") if "error" in result else ""
    return prompt_id, error_msg if error_msg else None, warnings

def wait_for_completion(cfg: dict, prompt_id: str, timeout: int = 120) -> dict:
    start = time.time()

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · image_with_comfyui.py (reported line 1313)May include surrounding context.

python
prompt_id = result.get("prompt_id")
    error_msg = result.get("error", {}).get("message", "") if "error" in result else ""
    return prompt_id, error_msg if error_msg else None, warnings

def wait_for_completion(cfg: dict, prompt_id: str, timeout: int = 120) -> dict:
    start = time.time()

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · image_with_comfyui.py (reported line 1317)May include surrounding context.

python
prompt_id = result.get("prompt_id")
    error_msg = result.get("error", {}).get("message", "") if "error" in result else ""
    return prompt_id, error_msg if error_msg else None, warnings

def wait_for_completion(cfg: dict, prompt_id: str, timeout: int = 120) -> dict:
    start = time.time()

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · image_with_comfyui.py (reported line 1320)May include surrounding context.

python
prompt_id = result.get("prompt_id")
    error_msg = result.get("error", {}).get("message", "") if "error" in result else ""
    return prompt_id, error_msg if error_msg else None, warnings

def wait_for_completion(cfg: dict, prompt_id: str, timeout: int = 120) -> dict:
    start = time.time()

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · image_with_comfyui.py (reported line 1323)May include surrounding context.

python
prompt_id = result.get("prompt_id")
    error_msg = result.get("error", {}).get("message", "") if "error" in result else ""
    return prompt_id, error_msg if error_msg else None, warnings

def wait_for_completion(cfg: dict, prompt_id: str, timeout: int = 120) -> dict:
    start = time.time()

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · image_with_comfyui.py (reported line 1324)May include surrounding context.

python
prompt_id = result.get("prompt_id")
    error_msg = result.get("error", {}).get("message", "") if "error" in result else ""
    return prompt_id, error_msg if error_msg else None, warnings

def wait_for_completion(cfg: dict, prompt_id: str, timeout: int = 120) -> dict:
    start = time.time()

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · image_with_comfyui.py (reported line 683)May include surrounding context.

python
def sanitize_filename(filename: str, output_dir: Path) -> str | None:
    """Sanitize a filename from a remote ComfyUI server.

    Prevents path traversal attacks (e.g. `../../../etc/passwd`) by:
    1. Stripping all directory components — only the bare basename is kept
    2. Rejecting empty names, `..`, `.`, or names containing path separators
    3. Verifying the final resolved path stays within output_dir

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · image_with_comfyui.py (reported line 897)May include surrounding context.

python
with open(workflow_path, "r", encoding="utf-8") as f:
        workflow = json.load(f)
    
    # Fill prompt node
    found = False
    for node_id, node_data in workflow.items():
        ct = node_data.get("class_type", "")

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · image_with_comfyui.py (reported line 964)May include surrounding context.

python
with open(workflow_path, "r", encoding="utf-8") as f:
        workflow = json.load(f)
    
    # Fill prompt node
    found = False
    for node_id, node_data in workflow.items():
        ct = node_data.get("class_type", "")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document explicitly tells the agent to delete staged files after sending them, which is a destructive filesystem operation affecting user-generated content. The file does not warn the user that temporary copies will be created and then removed, nor does it frame this behavior as something the user should expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This plain-text file contains the Chinese phrase "ComfyUI 格式" in otherwise English instructions. The file does not indicate a multilingual mode, user language choice, or a documented reason for mixing locales here, which can conflict with language/locale consistency policy.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This JSON manifest defines a full media-generation workflow but contains no natural-language description of when it should be invoked, what user intents it is meant to match, or any exclusion conditions. For manifest files, the absence of specific trigger scope can lead to overly broad or unintended invocation by surrounding tooling that relies on manifest metadata.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
config.json:2