comfy-cli
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
comfyCLI to perform system-level operations such as environment installation, launching background processes, and stopping instances. - [REMOTE_CODE_EXECUTION]: The tool facilitates the installation of 'custom nodes' from a registry. These nodes are third-party Python scripts that execute within the ComfyUI server context to extend its functionality.
- [EXTERNAL_DOWNLOADS]: The skill downloads software dependencies, ComfyUI core, and AI models from external sources including GitHub, Hugging Face, CivitAI, and user-specified URLs.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data files that could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Processes
workflow.jsonandsnapshot.jsonfiles inSKILL.md. - Boundary markers: No specific boundary markers or 'ignore' instructions are used for the processed JSON payloads.
- Capability inventory: Capabilities include network requests (
comfy model download), file system writes, and subprocess execution (comfy launch,comfy node install). - Sanitization: The skill relies on the structure of the input JSON; no explicit sanitization logic for embedded strings is described.
Audit Metadata