Skip to main content

comfyui

Generates images, video, and audio using ComfyUI with REST/WebSocket API for advanced workflows and parameter management.

Install this skill

or
0/100

Security score

The comfyui skill was audited on May 17, 2026 and we found 41 security issues across 2 threat categories, including 5 high-severity. Review the findings below before installing.

Categories Tested

Security Issues

medium line 108

Curl to non-GitHub URL

SourceSKILL.md
108curl -s http://127.0.0.1:8188/system_stats 2>/dev/null && echo "server: running"
high line 227

Curl to non-GitHub URL

SourceSKILL.md
227| "what's in the queue?" | REST | `curl http://HOST:8188/queue` (local) or `--host https://cloud.comfy.org` |
high line 228

Curl to non-GitHub URL

SourceSKILL.md
228| "cancel that" | REST | `curl -X POST http://HOST:8188/interrupt` |
high line 229

Curl to non-GitHub URL

SourceSKILL.md
229| "free GPU memory" | REST | `curl -X POST http://HOST:8188/free` |
medium line 406

Curl to non-GitHub URL

SourceSKILL.md
406curl -s http://127.0.0.1:8188/system_stats # health check
medium line 504

Curl to non-GitHub URL

SourceSKILL.md
504curl -X POST "http://127.0.0.1:8188/upload/image" \
medium line 509

Curl to non-GitHub URL

SourceSKILL.md
509curl -X POST "https://cloud.comfy.org/api/upload/image" \
medium line 539

Curl to non-GitHub URL

SourceSKILL.md
539curl -s http://127.0.0.1:8188/queue | python3 -m json.tool
medium line 540

Curl to non-GitHub URL

SourceSKILL.md
540curl -X POST http://127.0.0.1:8188/queue -d '{"clear": true}' # cancel pending
medium line 541

Curl to non-GitHub URL

SourceSKILL.md
541curl -X POST http://127.0.0.1:8188/interrupt # cancel running
medium line 542

Curl to non-GitHub URL

SourceSKILL.md
542curl -X POST http://127.0.0.1:8188/free \
high line 559

Curl to non-GitHub URL

SourceSKILL.md
559`curl http://127.0.0.1:8188/system_stats`.
high line 606

Curl to non-GitHub URL

SourceSKILL.md
606- [ ] `curl http://HOST:PORT/system_stats` returns JSON
low line 108

External URL reference

SourceSKILL.md
108curl -s http://127.0.0.1:8188/system_stats 2>/dev/null && echo "server: running"
low line 152

External URL reference

SourceSKILL.md
152# Local (defaults to http://127.0.0.1:8188)
low line 163

External URL reference

SourceSKILL.md
163--host https://cloud.comfy.org \
low line 227

External URL reference

SourceSKILL.md
227| "what's in the queue?" | REST | `curl http://HOST:8188/queue` (local) or `--host https://cloud.comfy.org` |
low line 228

External URL reference

SourceSKILL.md
228| "cancel that" | REST | `curl -X POST http://HOST:8188/interrupt` |
low line 229

External URL reference

SourceSKILL.md
229| "free GPU memory" | REST | `curl -X POST http://HOST:8188/free` |
low line 323

External URL reference

SourceSKILL.md
3231. Sign up at https://comfy.org/cloud
low line 324

External URL reference

SourceSKILL.md
3242. Generate an API key at https://platform.comfy.org/login
low line 334

External URL reference

SourceSKILL.md
334--host https://cloud.comfy.org \
low line 338

External URL reference

SourceSKILL.md
338**Pricing:** https://www.comfy.org/cloud/pricing
low line 350

External URL reference

SourceSKILL.md
350- **Windows (NVIDIA):** https://download.comfy.org/windows/nsis/x64
low line 351

External URL reference

SourceSKILL.md
351- **macOS (Apple Silicon):** https://comfy.org
low line 406

External URL reference

SourceSKILL.md
406curl -s http://127.0.0.1:8188/system_stats # health check
low line 420

External URL reference

SourceSKILL.md
420pip install torch torchvision torchaudio --extra-index-url https://download.pytorch.org/whl/cu130
low line 432

External URL reference

SourceSKILL.md
432--url "https://huggingface.co/stabilityai/stable-diffusion-xl-base-1.0/resolve/main/sd_xl_base_1.0.safetensors" \
low line 437

External URL reference

SourceSKILL.md
437--url "https://huggingface.co/stable-diffusion-v1-5/stable-diffusion-v1-5/resolve/main/v1-5-pruned-emaonly.safetensors" \
low line 442

External URL reference

SourceSKILL.md
442--url "https://huggingface.co/Comfy-Org/flux1-dev/resolve/main/flux1-dev-fp8.safetensors" \
low line 447

External URL reference

SourceSKILL.md
447--url "https://civitai.com/api/download/models/128713" \
low line 504

External URL reference

SourceSKILL.md
504curl -X POST "http://127.0.0.1:8188/upload/image" \
low line 509

External URL reference

SourceSKILL.md
509curl -X POST "https://cloud.comfy.org/api/upload/image" \
low line 516

External URL reference

SourceSKILL.md
516- **Base URL:** `https://cloud.comfy.org`
low line 539

External URL reference

SourceSKILL.md
539curl -s http://127.0.0.1:8188/queue | python3 -m json.tool
low line 540

External URL reference

SourceSKILL.md
540curl -X POST http://127.0.0.1:8188/queue -d '{"clear": true}' # cancel pending
low line 541

External URL reference

SourceSKILL.md
541curl -X POST http://127.0.0.1:8188/interrupt # cancel running
low line 542

External URL reference

SourceSKILL.md
542curl -X POST http://127.0.0.1:8188/free \
low line 547

External URL reference

SourceSKILL.md
547python3 scripts/fetch_logs.py --tail-queue --host https://cloud.comfy.org
low line 559

External URL reference

SourceSKILL.md
559`curl http://127.0.0.1:8188/system_stats`.
low line 606

External URL reference

SourceSKILL.md
606- [ ] `curl http://HOST:PORT/system_stats` returns JSON
Scanned on May 17, 2026
View Security Dashboard
Installation guide →