comfyui-gateway

Warn

Audited by Socket on Aug 16, 2026

1 alert found:

Security
SecurityMEDIUM
references/integration.md

No direct malware/backdoor behavior is present in this fragment because it is configuration-only. However, it contains multiple plaintext secrets and credentialed connection strings (JWT/webhook/API keys, Redis/DB credentials, S3/MinIO access keys) and includes permissive wildcard inbound security settings in some modes. This represents a serious security risk driven by credential leakage and misconfiguration, and it warrants immediate remediation (secret management, removal from repo/artifacts, tightening allowlists, and ensuring auth material is never empty in any non-lab environment).

Confidence: 74%Severity: 88%
Audit Metadata
Analyzed At
Aug 16, 2026, 01:29 AM
Package URL
pkg:socket/skills-sh/hainamchung%2Fagent-assistant%2Fcomfyui-gateway%2F@e33db1150873b5287838cbf55f5caa7e1d02e03ace30c3ecf4b732e5ee6699dd
Security Audit — socket — comfyui-gateway