Back to skill

Security audit

Comfyui Automation Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned, but it handles a RunningHub API key unsafely and can upload arbitrary user-provided local files to RunningHub without strong scoping or a separate upload confirmation.

Review before installing. Use a dedicated, low-privilege RunningHub API key, rotate it if it was typed into a visible terminal, and do not provide paths to sensitive local files. Prefer running in a restricted working directory or sandbox, and pin dependencies before installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:25
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
comfyui_automation.py:740
Finding

RunningHub API Key Entered Through an Echoing Terminal Prompt

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · comfyui_automation.py (reported line 741)May include surrounding context.

python
print("ComfyUI Automation Skill")
    print("=" * 50)
    
    # Get API key from user
    api_key = input("Please enter your RunningHub API key: ")
    
    # Get workflow identifier from user

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly instructs users to provide local file paths for automatic upload to RunningHub and to use network image URLs, but it does not warn that local files will be transmitted to a third-party service or that remote URLs may leak metadata and fetch untrusted content. In an automation skill that handles user-supplied media, this omission can cause unintended disclosure of sensitive files or privacy-impacting data sharing because users may not realize their inputs leave the local environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language content from the first section heading onward is presented only in Chinese, which effectively forces a specific language for users reading or operating the skill. The policy allows locale constraints only when users are given a choice or the restriction is clearly justified, neither of which is documented here.

Content

No source excerpt is available for this finding.

Tainted flow: 'workflow_id' from input (line 301, user input) → requests.get (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · comfyui_automation.py (reported line 79)May include surrounding context.

python
def get_workflow_json(self, workflow_id):
        """Get workflow JSON from RunningHub"""
        try:
            response = requests.get(
                f"{self.base_url}/workflow/{workflow_id}/json",
                headers=self.headers
            )

Tainted flow: 'workflow_identifier' from input (line 745, user input) → requests.get (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · comfyui_automation.py (reported line 204)May include surrounding context.

python
"""Get workflow information by identifier, or create a new one if not found"""
        try:
            # First try to get by workflowId
            response = requests.get(
                f"{self.base_url}/workflow/{workflow_identifier}",
                headers=self.headers
            )

Tainted flow: 'workflow_identifier' from input (line 745, user input) → requests.get (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · comfyui_automation.py (reported line 212)May include surrounding context.

python
return response.json()
            
            # If not found, try to search by nickname
            response = requests.get(
                f"{self.base_url}/workflow/search",
                headers=self.headers,
                params={"nickname": workflow_identifier}

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The skill accepts an arbitrary local file path from the user and uploads that file to cloud storage through RunningHub. In an agent-skill environment, this pattern is dangerous because it can be abused to exfiltrate sensitive local files if a user is socially engineered or if the surrounding agent passes untrusted instructions through to the operator.

Content

Scanner excerpt · comfyui_automation.py (reported line 589)May include surrounding context.

python
print(f"   ✓ Using URL: {image_input}")
                            break
                        elif os.path.exists(image_input):
                            uploaded_filename = self.upload_file(image_input)
                            if uploaded_filename:
                                node_values[key] = uploaded_filename
                                print(f"   ✓ Image uploaded: {uploaded_filename}")

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This code intentionally transmits collected prompts, materials, workflow parameters, and optional webhook data to a third-party API. In this skill context, external transmission is the core function, but it becomes security-relevant because user-provided content may include sensitive data and local files are also uploadable.

Content

Scanner excerpt · comfyui_automation.py (reported line 664)May include surrounding context.

python
if webhook_url:
                payload["webhook"] = webhook_url
            
            response = requests.post(
                api_endpoint,
                headers=self.headers,
                json=payload

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script sends workflow inputs, materials, prompts, and webhook information to an external cloud service but does not provide a clear user-facing warning about what specific data leaves the local environment. In a skill that can also upload local files, the lack of transparent disclosure materially increases the chance of accidental data exfiltration.

Content

No source excerpt is available for this finding.

Tainted flow: 'payload' from input (line 652, user input) → requests.post (network output)

Medium
Category
Data Flow
Confidence
95% confidence
Finding

The skill transmits user-provided materials, prompts, node inputs, and optionally a webhook URL to an external service without meaningful validation or strong consent around the data disclosure. This can expose sensitive local file contents after upload, private prompts, or internal callback endpoints to a third party, making the tainted outbound flow materially security-relevant in this context.

Content

Scanner excerpt · comfyui_automation.py (reported line 664)May include surrounding context.

python
if webhook_url:
                payload["webhook"] = webhook_url
            
            response = requests.post(
                api_endpoint,
                headers=self.headers,
                json=payload

Tainted flow: 'task_id' from input (line 813, user input) → requests.get (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · comfyui_automation.py (reported line 682)May include surrounding context.

python
def get_task_status(self, task_id):
        """Get task status"""
        try:
            response = requests.get(
                f"{self.base_url}/task/status",
                headers=self.headers,
                params={"taskId": task_id}

Tainted flow: 'task_id' from input (line 813, user input) → requests.get (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · comfyui_automation.py (reported line 700)May include surrounding context.

python
def get_task_result(self, task_id):
        """Get task result"""
        try:
            response = requests.get(
                f"{self.base_url}/task/result",
                headers=self.headers,
                params={"taskId": task_id}

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description is broad enough to enable ambiguous activation and unclear operational boundaries for a network-enabled automation skill. In agent environments, underspecified scope can cause the skill to be invoked in unintended contexts, increasing the chance of unsafe external calls or processing of untrusted workflows without clear user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README presents the skill description and operating instructions in Chinese and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern unless clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The predefined workflow names are fixed in Chinese, which imposes a specific language/locale assumption in user-facing behavior. The file does not provide an opt-in language selection or explain that the skill is intentionally region- or locale-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

Several user-facing setting descriptions are written in Chinese, while the rest of the manifest is in English, and the file does not state that the skill is intended only for Chinese-speaking users. This creates an implicit language constraint without offering a language choice or documenting the locale expectation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.