comfyui-media-workflows
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a Python script
scripts/inspect_workflow.pyand instructions to run it locally. This tool performs static analysis on ComfyUI JSON files to detect dangling links, cycles, and sensitive strings before execution.\n- [EXTERNAL_DOWNLOADS]: Instructions discuss downloading models and custom nodes from external sources. The skill provides extensive guidance on licensing, hash verification, and risk-ranking custom nodes to ensure security and mitigate supply chain risks.\n- [SAFE]: The skill processes untrusted ComfyUI JSON files as input. It addresses potential data exposure and injection risks by providing a bundled validation script that scans for sensitive information and structural anomalies before the data is processed.
Audit Metadata