comfyui-gateway

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Security
SecurityMEDIUM
references/integration.md

This fragment contains only configuration, not executable code; there is no direct evidence of intentional malware in the snippet itself. However, it presents a high security/supply-chain risk due to hardcoded sensitive secrets (API_KEYS, JWT_SECRET, WEBHOOK_SECRET, Redis/Postgres credentials, S3/MinIO credentials including default values) and permissive wildcard security settings (WEBHOOK_ALLOWED_DOMAINS='*', CORS_ORIGINS='*' in some variants). These factors could enable unauthorized access, job abuse, and data compromise if the configuration is exposed or deployed without compensating controls. Validate that real secrets are not committed/baked into artifacts, replace defaults, and tighten webhook/CORS policies in production.

Confidence: 70%Severity: 85%
Audit Metadata
Analyzed At
Aug 11, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fcomfyui-gateway%2F@fe2562a1396ba13122220f96b2bec4fe2bb51f50aa754947c73205b7f53167d1
Security Audit — socket — comfyui-gateway