T09 · Insecure Skill Coding Practices
- Location
scripts/comfy_api.py:633- Finding
Authentication Tokens and User Media Are Transmitted over Plaintext Connections
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its ComfyUI workflow purpose, but it needs Review because remote use can send prompts, media, and tokens over plaintext and it asks agents to persist local setup details.
Install only if you are comfortable with a local ComfyUI automation tool that can read selected media files, send prompts/workflows to a configured ComfyUI server, and write generated outputs. Prefer loopback-only ComfyUI or a TLS-protected remote endpoint; avoid using tokens with this skill over remote plaintext HTTP/WS. Review or disable the persistent model/workflow cache before letting an agent scan local model directories, run with pinned dependencies in a dedicated environment, and use voice-cloning capabilities only with clear consent.
scripts/comfy_api.py:633Authentication Tokens and User Media Are Transmitted over Plaintext Connections
scripts/comfy_run.py:1561The Primary CLI Declares Authentication Support but Does Not Propagate Credentials
skill.json:18Runtime Dependencies Are Installed without Reproducible Version or Integrity Pinning
A description-behavior mismatch is dangerous because it causes operators and agents to trust the skill for one purpose while it apparently performs materially different actions. If the implementation rewrites local JSON instead of safely inspecting/executing ComfyUI workflows, users may unintentionally expose files to modification, lose data integrity, or send incorrect inputs under false assumptions about what the skill does.
Referenced artifact was not completely inspected
`MODELS_INVENTORY.md` and `WORKFLOWS_SUMMARY.md` serve as the agent's persistent knowledge base for the user's actual ComfyUI setup. Use them to cache learned i
Referenced artifact was not completely inspected
`MODELS_INVENTORY.md` and `WORKFLOWS_SUMMARY.md` serve as the agent's persistent knowledge base for the user's actual ComfyUI setup. Use them to cache learned i
Referenced artifact was not completely inspected
`MODELS_INVENTORY.md` and `WORKFLOWS_SUMMARY.md` serve as the agent's persistent knowledge base for the user's actual ComfyUI setup. Use them to cache learned i
Referenced artifact was not completely inspected
`MODELS_INVENTORY.md` and `WORKFLOWS_SUMMARY.md` serve as the agent's persistent knowledge base for the user's actual ComfyUI setup. Use them to cache learned i
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
2. Run `--inspect` to verify it loads and converts correctly
3. Run `--dry-run` to see the API prompt without executing
4. Test with real execution
5. Update SKILL.md decision tree and quick reference table if needed
### Common Issues with New Workflows
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
help="Inspect workflow and output machine-readable JSON")
p.add_argument("--dry-run", action="store_true", help="Convert to API format and print (don't run)")
p.add_argument("--queue", action="store_true",
help="Submit to ComfyUI queue and return immediately (print prompt_id)")
p.add_argument("--status", nargs="*", metavar="PROMPT_ID",
help="Check job status. No args = show queue. With prompt_ids = check specific jobs.")
p.add_argument("--no-validate", action="store_true",
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
help="Submit to ComfyUI queue and return immediately (print prompt_id)")
p.add_argument("--status", nargs="*", metavar="PROMPT_ID",
help="Check job status. No args = show queue. With prompt_ids = check specific jobs.")
p.add_argument("--no-validate", action="store_true",
help="Skip input validation (not recommended)")
# Input customization
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
help="Submit to ComfyUI queue and return immediately (print prompt_id)")
p.add_argument("--status", nargs="*", metavar="PROMPT_ID",
help="Check job status. No args = show queue. With prompt_ids = check specific jobs.")
p.add_argument("--no-validate", action="store_true",
help="Skip input validation (not recommended)")
# Input customization
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
help="Submit to ComfyUI queue and return immediately (print prompt_id)")
p.add_argument("--status", nargs="*", metavar="PROMPT_ID",
help="Check job status. No args = show queue. With prompt_ids = check specific jobs.")
p.add_argument("--no-validate", action="store_true",
help="Skip input validation (not recommended)")
# Input customization
The skill makes race/ethnicity a mandatory attribute in character descriptions without requiring user need, consent, or contextual justification. This encourages unnecessary generation and propagation of sensitive demographic data, which can lead to profiling, biased outputs, or inappropriate handling of protected attributes in routine content creation workflows.
The inventory explicitly advertises "zero-shot voice cloning" capability without any accompanying consent, impersonation, or privacy safeguards. In a skill intended to help agents discover and use installed media-generation models, this omission can normalize or facilitate misuse for impersonation, fraud, or non-consensual voice synthesis.
The skill advertises and instructs use of capabilities including environment access, file reads/writes, networking, and shell execution, but it does not declare an explicit tool scope or permissions boundary. That omission increases the chance an agent will invoke more powerful tools than necessary without clear user-visible constraints, especially given the workflow includes remote server interaction and local file modification.
The read-only warning conflicts with later instructions to remove and update file contents, creating ambiguous operational guidance. Ambiguity around write permissions is risky in agent settings because it can normalize unexpected file modification and make it harder to distinguish legitimate maintenance from unsafe persistence behavior.
The skill directs the agent to store user-specific workflow, model, path, and environment details in persistent files without any privacy, retention, or sensitivity guidance. This creates a real risk of collecting and reusing local system information across sessions in ways the user did not explicitly authorize, potentially exposing filesystem layout, installed assets, or tokens by association.
Persistent cross-session caching of user-specific environment data increases exposure because information about installed models, local directories, workflow capabilities, and operational quirks can accumulate over time. In an agent context, that persistence broadens the blast radius of a mistake or compromise and may violate least-retention expectations.
Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.
import json, urllib.request
api = json.load(open("/tmp/api.json"))
payload = json.dumps({"prompt": api}).encode()
req = urllib.request.Request("http://127.0.0.1:8188/prompt",
data=payload, headers={"Content-Type": "application/json"})
try:
resp = json.loads(urllib.request.urlopen(req).read())
The upload_image function reads a local file and sends its contents over HTTP to the configured ComfyUI server, but there is no print/log statement, confirmation, or warning comment indicating that local image data will be transmitted. Because this is a code file, network transmission of user data should have some visible disclosure unless clearly surfaced elsewhere.
The queue_prompt function serializes the full prompt and transmits it to the ComfyUI server via HTTP, but the code contains no user-facing disclosure such as logging, confirmation, or warning comment. Workflow prompts can contain user text and other potentially sensitive content, so this network transfer should be surfaced to users.
The skill can spawn a host-level control script to start local ComfyUI automatically when the service is unavailable. In an agent/tooling context, this expands the tool from a workflow client into a local process launcher, which is dangerous because invoking the skill can cause unexpected host-side execution and persistence-related behavior outside the immediate workflow task.
The code makes HTTP requests to a dynamic server target derived from user-provided --server or imported configuration, with no apparent allowlisting or validation. In a tool/agent context this can be abused to reach arbitrary internal or local network services, turning the skill into an SSRF-capable network client.
"""Make sure ComfyUI is running."""
import urllib.request
try:
urllib.request.urlopen(f"http://{server}/", timeout=3)
return True
except Exception:
pass
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
print("ComfyUI not running. Starting via comfy_control.sh ensure ...")
try:
result = subprocess.run(
["bash", CTRL_SCRIPT, "ensure"],
capture_output=True, text=True, timeout=200,
)
The diagnostic mode runs Windows PowerShell, queries processes, event logs, and GPU state, which goes well beyond executing a ComfyUI workflow. In an agent setting this is sensitive host reconnaissance: it can expose system details and widens the consequences of invoking the skill, especially across WSL/Windows boundaries.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
}
"""
try:
result = subprocess.run(
[ps_exe, "-NoProfile", "-Command", ps_cmd],
capture_output=True, text=True, timeout=15,
)
The VHS_VideoCombine node is configured with save_output=true and a filename_prefix that writes files under video/%date... , which means running the workflow persists generated media to disk. In this JSON there is no accompanying warning text, confirmation mechanism, or explanatory note near that save behavior, so users are not clearly informed that execution writes output files automatically.
No suspicious patterns detected.