comfy-build

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acknowledges the risk of processing attacker-controlled data from external sources such as build logs and custom node package metadata.\n
  • Ingestion points: Processes logs from comfy build release logs and scans local file system metadata during environment initialization.\n
  • Boundary markers: Explicitly instructs the agent to treat build logs as "attacker-controlled text" and forbids executing any commands or copying literals found within them.\n
  • Capability inventory: Access to comfy-cli for environment scanning, configuration management, and platform synchronization.\n
  • Sanitization: Requires the agent to describe findings in its own words and mandates explicit user confirmation before executing potentially destructive or billable actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 01:46 PM
Security Audit — agent-trust-hub — comfy-build