comfyui-mcp-agent
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's capabilities largely match its stated ComfyUI-control purpose, and the main package/panel sources appear same-org and official. However, it materially expands the agent's footprint: unpinned `npx` execution, remote tunnel exposure, and installation of arbitrary third-party custom node repos and their dependencies. Data flows mostly target expected services, not obvious exfiltration endpoints, so this is not confirmed malware; the main concern is substantial supply-chain and execution-trust risk that is only partly justified by the workflow-management use case.
Confidence: 87%Severity: 74%
Audit Metadata