Local-first, agent-native control plane for ComfyUI — MCP server + autonomous sidebar agent that drives your live graph in natural language on ANY LLM: Claude/ChatGPT/Gemini on your subscription (no API key), free local models via Ollama (fully offline),
- capability exposure inferred + 35
- tool safety inferred + 17
- trust mitigators mixed − 22
inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
grade last moved 1w ago · see ecosystem CVEs →
- B · 25 → B · 30
- B · 31 → B · 25
- C · 36 → B · 31
- B · 24 → C · 36
- C · 36 → B · 24
- C · 44 → C · 36
- C · 59 → C · 44
- C · 47 → C · 59
- C · 49 → C · 47
- D · 66 → C · 49
- D · 78 → D · 66
- E · 86 → D · 78
- D · 79 → E · 86
- D · 67 → D · 79
- D · 79 → D · 67
- D · 67 → D · 79
- D · 79 → D · 67
- E · 91 → D · 79
- D · 79 → E · 91
No known CVEs for this server.
- high dangerous code
obfuscated payload: dynamic require()/import()
- medium toxic flow (lethal trifecta)
lethal trifecta reachable across this server's tool + source surface: private-data access + untrusted-content ingestion + network exfil (a leg is proven only in the analyzed source)
- low dangerous code
env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- low dangerous code
env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
analyzed v0.52.203 · analyzer v33 · 1w ago
skills & prompt files 42
- skill package/plugin/skills/ai-toolkit-trainer/SKILL.md
- skill package/plugin/skills/anima-base/SKILL.md
- skill package/plugin/skills/anima-lora-trainer/SKILL.md
- skill package/plugin/skills/civitai/SKILL.md
- skill package/plugin/skills/color-correction/SKILL.md
- skill package/plugin/skills/comfyui-core/SKILL.md
- skill package/plugin/skills/comfyui-frontend-extensions/SKILL.md
- skill package/plugin/skills/comfyui-launch-flags/SKILL.md
- skill package/plugin/skills/comfyui-node-registry/SKILL.md
- skill package/plugin/skills/debug-render/SKILL.md
- skill package/plugin/skills/director/SKILL.md
- skill package/plugin/skills/ernie-image/SKILL.md
- skill package/plugin/skills/flux-txt2img/SKILL.md
- skill package/plugin/skills/ideogram-ultra/SKILL.md
- skill package/plugin/skills/installer-packs/SKILL.md
- skill package/plugin/skills/krea2-identity-edit/SKILL.md
- skill package/plugin/skills/krea2-txt2img/SKILL.md
- skill package/plugin/skills/local-llm-free/SKILL.md
- skill package/plugin/skills/lora-manager/SKILL.md
- skill package/plugin/skills/ltx-director/SKILL.md
- skill package/plugin/skills/ltxv2-video/SKILL.md
- skill package/plugin/skills/minimax-h3-video/SKILL.md
- skill package/plugin/skills/model-compatibility/SKILL.md
- skill package/plugin/skills/model-registry/SKILL.md
- skill package/plugin/skills/panel-node-pack-sync/SKILL.md
- skill package/plugin/skills/panel-operations/SKILL.md
- skill package/plugin/skills/prompt-engineering/SKILL.md
- skill package/plugin/skills/qwen-image-edit/SKILL.md
- skill package/plugin/skills/qwen-txt2img/SKILL.md
- skill package/plugin/skills/report-bug/SKILL.md
- skill package/plugin/skills/rgthree/SKILL.md
- skill package/plugin/skills/train-character-lora/SKILL.md
- skill package/plugin/skills/triton-sageattention/SKILL.md
- skill package/plugin/skills/troubleshooting/SKILL.md
- skill package/plugin/skills/video-extend/SKILL.md
- skill package/plugin/skills/video-upscale/SKILL.md
- skill package/plugin/skills/wan-flf-video/SKILL.md
- skill package/plugin/skills/wan-multitalk/SKILL.md
- skill package/plugin/skills/wan-scail-replacement/SKILL.md
- skill package/plugin/skills/wan-t2v-video/SKILL.md
- skill package/plugin/skills/workflow-layout/SKILL.md
- skill package/plugin/skills/z-image-txt2img/SKILL.md
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of artokun.