Back to skill

Security audit

Comfyui Workflow

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its ComfyUI workflow purpose, but it needs Review because remote use can send prompts, media, and tokens over plaintext and it asks agents to persist local setup details.

Install only if you are comfortable with a local ComfyUI automation tool that can read selected media files, send prompts/workflows to a configured ComfyUI server, and write generated outputs. Prefer loopback-only ComfyUI or a TLS-protected remote endpoint; avoid using tokens with this skill over remote plaintext HTTP/WS. Review or disable the persistent model/workflow cache before letting an agent scan local model directories, run with pinned dependencies in a dedicated environment, and use voice-cloning capabilities only with clear consent.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/comfy_api.py:633
Finding

Authentication Tokens and User Media Are Transmitted over Plaintext Connections

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/comfy_run.py:1561
Finding

The Primary CLI Declares Authentication Support but Does Not Propagate Credentials

Content
View full analysis
= len(image_nodes): print(f" Warning: More images ({len(args.image)}) than image loader" f" nodes ({len(image_nodes)}). Extra images ignored.") break nid, ct, field, _old = image_nodes[i] server_name = upload_image(server, img_path) api[nid]["inputs"][field] = server_name print(f" Uploaded {os.path.basename(img_path)} → node {nid} ({ct})") # --- Audio inputs --- if args.audio: audio_nodes = info["audio_inputs"] for i, audio_path in enumerate(args.audio): if i >= len(audio_nodes): print(f" Warning: More audio files than audio loader nodes. Extra ignored.") break nid, ct, field, _old = audio_nodes[i] server_name = upload_image(server, audio_path) api[nid]["inputs"][field] = server_name print(f" Uploaded {os.path.basename(audio_path)} → node {nid} ({ct})") # --- Video inputs --- if args.video: video_nodes = info["video_inputs"] for i, vid_path in enumerate(args.video): if i >= len(video_nodes): print(f" Warning: More video files than video loader nodes. Extra ignored.") break nid, ct, field, _old = video_nodes[i] server_name = upload_i ...[truncated 3693 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
skill.json:18
Finding

Runtime Dependencies Are Installed without Reproducible Version or Integrity Pinning

Content
View full analysis
=3.10", "packages": [ "websocket-client>=1.0.0", "requests" ], "binaries": [ { "name": "python3", "version": ">=3.10", "description": "Python interpreter for running workflow scripts" }, { "name": "pip", "description": "Python package manager for installing dependencies" } ] }, ``` ```json "dependencies": { "websocket-client": ">=1.0.0" }, ``` The installation instructions also use unconstrained package resolution: ```bash pip install websocket-client requests ``` ### Technical Analysis The Skill installs `requests` without any version constraint and allows any `websocket-client` release newer than version 1.0.0. No lock file, package hashes, or explicit trusted package index is supplied. The identified package names are established third-party projects, and the audit did not find evidence of typosquatting, dependency confusion, or a currently malicious release. The risk is prospective and reproducibility-related: the effective code installed alongside the Skill can change after the Skill itself has been reviewed. A future compromised, removed, or incompatible dependency release could therefore execute in the same Python environment as the Skill. Broad lower-bound-only constraints also make it difficult to reproduce a reviewed deployment or determine which dependency implementation was active during an incident. ### Attack Path 1. A user follows the documented `pip install websocket-client requests` command. 2. The package resolver selects the newest releases available from the configured package index at installation time. 3. A future release is compromised, maliciously replaced, or contains a security regression. 4. The user inst ...[truncated 978 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (48)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A description-behavior mismatch is dangerous because it causes operators and agents to trust the skill for one purpose while it apparently performs materially different actions. If the implementation rewrites local JSON instead of safely inspecting/executing ComfyUI workflows, users may unintentionally expose files to modification, lose data integrity, or send incorrect inputs under false assumptions about what the skill does.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

md
`MODELS_INVENTORY.md` and `WORKFLOWS_SUMMARY.md` serve as the agent's persistent knowledge base for the user's actual ComfyUI setup. Use them to cache learned i

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

md
`MODELS_INVENTORY.md` and `WORKFLOWS_SUMMARY.md` serve as the agent's persistent knowledge base for the user's actual ComfyUI setup. Use them to cache learned i

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 218)May include surrounding context.

md
`MODELS_INVENTORY.md` and `WORKFLOWS_SUMMARY.md` serve as the agent's persistent knowledge base for the user's actual ComfyUI setup. Use them to cache learned i

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 240)May include surrounding context.

md
`MODELS_INVENTORY.md` and `WORKFLOWS_SUMMARY.md` serve as the agent's persistent knowledge base for the user's actual ComfyUI setup. Use them to cache learned i

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/maintenance.md (reported line 141)May include surrounding context.

md
2. Run `--inspect` to verify it loads and converts correctly
3. Run `--dry-run` to see the API prompt without executing
4. Test with real execution
5. Update SKILL.md decision tree and quick reference table if needed

### Common Issues with New Workflows

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/comfy_run.py (reported line 2025)May include surrounding context.

python
help="Inspect workflow and output machine-readable JSON")
    p.add_argument("--dry-run", action="store_true", help="Convert to API format and print (don't run)")
    p.add_argument("--queue", action="store_true",
                   help="Submit to ComfyUI queue and return immediately (print prompt_id)")
    p.add_argument("--status", nargs="*", metavar="PROMPT_ID",
                   help="Check job status. No args = show queue. With prompt_ids = check specific jobs.")
    p.add_argument("--no-validate", action="store_true",

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 186)May include surrounding context.

md
help="Submit to ComfyUI queue and return immediately (print prompt_id)")
    p.add_argument("--status", nargs="*", metavar="PROMPT_ID",
                   help="Check job status. No args = show queue. With prompt_ids = check specific jobs.")
    p.add_argument("--no-validate", action="store_true",
                   help="Skip input validation (not recommended)")

    # Input customization

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/comfy_run.py (reported line 2028)May include surrounding context.

python
help="Submit to ComfyUI queue and return immediately (print prompt_id)")
    p.add_argument("--status", nargs="*", metavar="PROMPT_ID",
                   help="Check job status. No args = show queue. With prompt_ids = check specific jobs.")
    p.add_argument("--no-validate", action="store_true",
                   help="Skip input validation (not recommended)")

    # Input customization

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/comfy_run.py (reported line 2271)May include surrounding context.

python
help="Submit to ComfyUI queue and return immediately (print prompt_id)")
    p.add_argument("--status", nargs="*", metavar="PROMPT_ID",
                   help="Check job status. No args = show queue. With prompt_ids = check specific jobs.")
    p.add_argument("--no-validate", action="store_true",
                   help="Skip input validation (not recommended)")

    # Input customization

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill makes race/ethnicity a mandatory attribute in character descriptions without requiring user need, consent, or contextual justification. This encourages unnecessary generation and propagation of sensitive demographic data, which can lead to profiling, biased outputs, or inappropriate handling of protected attributes in routine content creation workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The inventory explicitly advertises "zero-shot voice cloning" capability without any accompanying consent, impersonation, or privacy safeguards. In a skill intended to help agents discover and use installed media-generation models, this omission can normalize or facilitate misuse for impersonation, fraud, or non-consensual voice synthesis.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises and instructs use of capabilities including environment access, file reads/writes, networking, and shell execution, but it does not declare an explicit tool scope or permissions boundary. That omission increases the chance an agent will invoke more powerful tools than necessary without clear user-visible constraints, especially given the workflow includes remote server interaction and local file modification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The read-only warning conflicts with later instructions to remove and update file contents, creating ambiguous operational guidance. Ambiguity around write permissions is risky in agent settings because it can normalize unexpected file modification and make it harder to distinguish legitimate maintenance from unsafe persistence behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill directs the agent to store user-specific workflow, model, path, and environment details in persistent files without any privacy, retention, or sensitivity guidance. This creates a real risk of collecting and reusing local system information across sessions in ways the user did not explicitly authorize, potentially exposing filesystem layout, installed assets, or tokens by association.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Persistent cross-session caching of user-specific environment data increases exposure because information about installed models, local directories, workflow capabilities, and operational quirks can accumulate over time. In an agent context, that persistence broadens the blast radius of a mistake or compromise and may violate least-retention expectations.

Content

No source excerpt is available for this finding.

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · references/maintenance.md (reported line 182)May include surrounding context.

md
import json, urllib.request
api = json.load(open("/tmp/api.json"))
payload = json.dumps({"prompt": api}).encode()
req = urllib.request.Request("http://127.0.0.1:8188/prompt",
                             data=payload, headers={"Content-Type": "application/json"})
try:
    resp = json.loads(urllib.request.urlopen(req).read())

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The upload_image function reads a local file and sends its contents over HTTP to the configured ComfyUI server, but there is no print/log statement, confirmation, or warning comment indicating that local image data will be transmitted. Because this is a code file, network transmission of user data should have some visible disclosure unless clearly surfaced elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The queue_prompt function serializes the full prompt and transmits it to the ComfyUI server via HTTP, but the code contains no user-facing disclosure such as logging, confirmation, or warning comment. Workflow prompts can contain user text and other potentially sensitive content, so this network transfer should be surfaced to users.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill can spawn a host-level control script to start local ComfyUI automatically when the service is unavailable. In an agent/tooling context, this expands the tool from a workflow client into a local process launcher, which is dangerous because invoking the skill can cause unexpected host-side execution and persistence-related behavior outside the immediate workflow task.

Content

No source excerpt is available for this finding.

Dynamic Request Target

Medium
Category
Server-Side Request Forgery
Confidence
91% confidence
Finding

The code makes HTTP requests to a dynamic server target derived from user-provided --server or imported configuration, with no apparent allowlisting or validation. In a tool/agent context this can be abused to reach arbitrary internal or local network services, turning the skill into an SSRF-capable network client.

Content

Scanner excerpt · scripts/comfy_run.py (reported line 1700)May include surrounding context.

python
"""Make sure ComfyUI is running."""
    import urllib.request
    try:
        urllib.request.urlopen(f"http://{server}/", timeout=3)
        return True
    except Exception:
        pass

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/comfy_run.py (reported line 1707)May include surrounding context.

python
print("ComfyUI not running. Starting via comfy_control.sh ensure ...")
    try:
        result = subprocess.run(
            ["bash", CTRL_SCRIPT, "ensure"],
            capture_output=True, text=True, timeout=200,
        )

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The diagnostic mode runs Windows PowerShell, queries processes, event logs, and GPU state, which goes well beyond executing a ComfyUI workflow. In an agent setting this is sensitive host reconnaissance: it can expose system details and widens the consequences of invoking the skill, especially across WSL/Windows boundaries.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/comfy_run.py (reported line 1966)May include surrounding context.

python
}
"""
    try:
        result = subprocess.run(
            [ps_exe, "-NoProfile", "-Command", ps_cmd],
            capture_output=True, text=True, timeout=15,
        )

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The VHS_VideoCombine node is configured with save_output=true and a filename_prefix that writes files under video/%date... , which means running the workflow persists generated media to disk. In this JSON there is no accompanying warning text, confirmation mechanism, or explanatory note near that save behavior, so users are not clearly informed that execution writes output files automatically.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.