comfy-media

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The declared capabilities mostly fit the stated purpose of local media review and export, and data flow stays local/localhost. The main concern is install trust: the core `comfy-media` tool is not verifiably sourced from an official publisher in the provided evidence, and the skill adds a transitive dependency on `comfy-tools-setup`; `npx hyperframes` is more defensible because it is documented and registry-backed. No clear credential harvesting, covert exfiltration, or malicious mismatch is shown.

Confidence: 83%Severity: 62%
Audit Metadata
Analyzed At
May 9, 2026, 03:03 AM
Package URL
pkg:socket/skills-sh/quinteroac%2Fcomfy-agent-tools%2Fcomfy-media%2F@549d559c81738ac30b067fe7967bc74ab070e4ad
Security Audit — socket — comfy-media