comfy-cli

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the comfy CLI to perform system-level operations such as environment installation, launching background processes, and stopping instances.
  • [REMOTE_CODE_EXECUTION]: The tool facilitates the installation of 'custom nodes' from a registry. These nodes are third-party Python scripts that execute within the ComfyUI server context to extend its functionality.
  • [EXTERNAL_DOWNLOADS]: The skill downloads software dependencies, ComfyUI core, and AI models from external sources including GitHub, Hugging Face, CivitAI, and user-specified URLs.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data files that could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Processes workflow.json and snapshot.json files in SKILL.md.
  • Boundary markers: No specific boundary markers or 'ignore' instructions are used for the processed JSON payloads.
  • Capability inventory: Capabilities include network requests (comfy model download), file system writes, and subprocess execution (comfy launch, comfy node install).
  • Sanitization: The skill relies on the structure of the input JSON; no explicit sanitization logic for embedded strings is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 04:42 AM
Security Audit — agent-trust-hub — comfy-cli