comfyui

Warn

Audited by Socket on Sep 13, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/auto_fix_deps.py

The fragment is a legitimate dependency-repair CLI, but it performs privileged package and model installation from externally supplied data. The primary concrete security issue is that sensitive API tokens are included in logged subprocess command lines. Arbitrary model URLs are also accepted without validation or integrity checking, so users must trust the workflow, source mapping, Comfy CLI, and downloaded artifacts. No direct malware, data exfiltration, shell injection, or obfuscated payload is evident in this module.

Confidence: 95%Severity: 62%
Audit Metadata
Analyzed At
Sep 13, 2026, 07:36 PM
Package URL
pkg:socket/skills-sh/aston1690%2Fhermes-creative-skills%2Fcomfyui%2F@dfcdd66f733c2aee3967fc1c90323294fb76ff919223025b776a0e66fcdd91cf
Security Audit — socket — comfyui