skills/comfy-org/comfy-skills/comfy/Gen Agent Trust Hub

comfy

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected.
  • [CREDENTIALS_UNSAFE]: The skill demonstrates safe credential management by instructing users to use environment variables for API keys and providing clear placeholders (e.g., comfyui-...).
  • [EXTERNAL_DOWNLOADS]: The skill connects to official comfy.org service endpoints for image generation and references documentation from the official vendor domain.
  • [COMMAND_EXECUTION]: Provides standard configuration commands for the OpenClaw environment to set up and authorize the MCP server.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for processing user-provided prompts and files as inputs to media generation workflows. It uses standard tool-calling patterns to pass this data to the hosted service.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 02:50 PM
Security Audit — agent-trust-hub — comfy