T08 · Insecure Dependencies
- Location
README.md:25- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears purpose-aligned, but it handles a RunningHub API key unsafely and can upload arbitrary user-provided local files to RunningHub without strong scoping or a separate upload confirmation.
Review before installing. Use a dedicated, low-privilege RunningHub API key, rotate it if it was typed into a visible terminal, and do not provide paths to sensitive local files. Prefer running in a restricted working directory or sandbox, and pin dependencies before installation.
README.md:25Unpinned Third-Party Dependency Installation
comfyui_automation.py:740RunningHub API Key Entered Through an Echoing Terminal Prompt
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
print("ComfyUI Automation Skill")
print("=" * 50)
# Get API key from user
api_key = input("Please enter your RunningHub API key: ")
# Get workflow identifier from user
The README explicitly instructs users to provide local file paths for automatic upload to RunningHub and to use network image URLs, but it does not warn that local files will be transmitted to a third-party service or that remote URLs may leak metadata and fetch untrusted content. In an automation skill that handles user-supplied media, this omission can cause unintended disclosure of sensitive files or privacy-impacting data sharing because users may not realize their inputs leave the local environment.
The natural-language content from the first section heading onward is presented only in Chinese, which effectively forces a specific language for users reading or operating the skill. The policy allows locale constraints only when users are given a choice or the restriction is clearly justified, neither of which is documented here.
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
def get_workflow_json(self, workflow_id):
"""Get workflow JSON from RunningHub"""
try:
response = requests.get(
f"{self.base_url}/workflow/{workflow_id}/json",
headers=self.headers
)
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
"""Get workflow information by identifier, or create a new one if not found"""
try:
# First try to get by workflowId
response = requests.get(
f"{self.base_url}/workflow/{workflow_identifier}",
headers=self.headers
)
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
return response.json()
# If not found, try to search by nickname
response = requests.get(
f"{self.base_url}/workflow/search",
headers=self.headers,
params={"nickname": workflow_identifier}
The skill accepts an arbitrary local file path from the user and uploads that file to cloud storage through RunningHub. In an agent-skill environment, this pattern is dangerous because it can be abused to exfiltrate sensitive local files if a user is socially engineered or if the surrounding agent passes untrusted instructions through to the operator.
print(f" ✓ Using URL: {image_input}")
break
elif os.path.exists(image_input):
uploaded_filename = self.upload_file(image_input)
if uploaded_filename:
node_values[key] = uploaded_filename
print(f" ✓ Image uploaded: {uploaded_filename}")
This code intentionally transmits collected prompts, materials, workflow parameters, and optional webhook data to a third-party API. In this skill context, external transmission is the core function, but it becomes security-relevant because user-provided content may include sensitive data and local files are also uploadable.
if webhook_url:
payload["webhook"] = webhook_url
response = requests.post(
api_endpoint,
headers=self.headers,
json=payload
The script sends workflow inputs, materials, prompts, and webhook information to an external cloud service but does not provide a clear user-facing warning about what specific data leaves the local environment. In a skill that can also upload local files, the lack of transparent disclosure materially increases the chance of accidental data exfiltration.
The skill transmits user-provided materials, prompts, node inputs, and optionally a webhook URL to an external service without meaningful validation or strong consent around the data disclosure. This can expose sensitive local file contents after upload, private prompts, or internal callback endpoints to a third party, making the tainted outbound flow materially security-relevant in this context.
if webhook_url:
payload["webhook"] = webhook_url
response = requests.post(
api_endpoint,
headers=self.headers,
json=payload
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
def get_task_status(self, task_id):
"""Get task status"""
try:
response = requests.get(
f"{self.base_url}/task/status",
headers=self.headers,
params={"taskId": task_id}
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
def get_task_result(self, task_id):
"""Get task result"""
try:
response = requests.get(
f"{self.base_url}/task/result",
headers=self.headers,
params={"taskId": task_id}
The manifest description is broad enough to enable ambiguous activation and unclear operational boundaries for a network-enabled automation skill. In agent environments, underspecified scope can cause the skill to be invoked in unintended contexts, increasing the chance of unsafe external calls or processing of untrusted workflows without clear user intent.
The README presents the skill description and operating instructions in Chinese and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern unless clearly justified.
The predefined workflow names are fixed in Chinese, which imposes a specific language/locale assumption in user-facing behavior. The file does not provide an opt-in language selection or explain that the skill is intentionally region- or locale-specific.
Several user-facing setting descriptions are written in Chinese, while the rest of the manifest is in English, and the file does not state that the skill is intended only for Chinese-speaking users. This creates an implicit language constraint without offering a language choice or documenting the locale expectation.
No suspicious patterns detected.