comfyui
Warn
Audited by Socket on Sep 13, 2026
1 alert found:
AnomalyAnomalyscripts/auto_fix_deps.py
LOWAnomalyLOW
scripts/auto_fix_deps.py
The fragment is a legitimate dependency-repair CLI, but it performs privileged package and model installation from externally supplied data. The primary concrete security issue is that sensitive API tokens are included in logged subprocess command lines. Arbitrary model URLs are also accepted without validation or integrity checking, so users must trust the workflow, source mapping, Comfy CLI, and downloaded artifacts. No direct malware, data exfiltration, shell injection, or obfuscated payload is evident in this module.
Confidence: 95%Severity: 62%
Audit Metadata