comfy-tools-setup

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, but it installs executable tooling directly from an unpinned GitHub repository and includes transitive skill installation guidance. No credential harvesting or off-purpose data flows are evident, so this looks more like moderate supply-chain risk than malware.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
May 8, 2026, 12:14 AM
Package URL
pkg:socket/skills-sh/quinteroac%2Fcomfy-agent-tools%2Fcomfy-tools-setup%2F@74ed381c7881990be97dbe3cdaf09a4d73457c00
Security Audit — socket — comfy-tools-setup