comfyui-mcp-agent

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's capabilities largely match its stated ComfyUI-control purpose, and the main package/panel sources appear same-org and official. However, it materially expands the agent's footprint: unpinned `npx` execution, remote tunnel exposure, and installation of arbitrary third-party custom node repos and their dependencies. Data flows mostly target expected services, not obvious exfiltration endpoints, so this is not confirmed malware; the main concern is substantial supply-chain and execution-trust risk that is only partly justified by the workflow-management use case.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:33 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fcomfyui-mcp-agent%2F@76c4911ce06890e8c90bd8f3353ca7da99b6fc4dfea795b7132f087307bee748
Security Audit — socket — comfyui-mcp-agent