Atlas / MCP servers / artokun / ComfyUI

ComfyUIBLOCK

mcp/artokun/comfyui-9

Local-first, agent-native control plane for ComfyUI — MCP server + sidebar agent that generates images, video & audio, authors and runs workflows, and edits your live graph in natural language on ANY LLM (Claude, ChatGPT, Gemini, offline Ollama, or any hosted model). 178 tools, 36 AI skills, 55 inst

Verdict
BLOCK
Grade
F
Trust score
25 /100
Exposed tools
70 50r · 16w · 4d
Transport
stdio · streamable-http
License
MIT
Stars
773
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[!IMPORTANT] This project is no longer maintained. ComfyUI now ships official agent and MCP tooling — [Comfy Agent](https://comfy.org/agent) and [Comfy MCP](https://comfy.org/mcp) — built and supported by the Comfy-Org team with deeper integration than a community project can match. If you’re looking for an MCP server or AI agent for ComfyUI, use the official tooling. This repo will remain public as a reference, but no new features, bug fixes, or dependency updates will be made. Issues and pull requests close when the repo is archived on 2026-10-09. The community Discord goes read-only the same day, with its threads left up as a searchable archive. Thanks to everyone who used, starred, forked, and contributed to this project. It was a good run. :rocket: The full story is in the goodbye post. Looking for a ComfyUI or generative-AI integration expert? I take on custom solutions — reach me by email at [email protected] or on LinkedIn.

<img src="docs/images/demo-poster.jpg" width="760" alt="The Agent panel driving ComfyUI end to end. Click to watch the demo">

The Agent panel driving ComfyUI end to end. It reads what is installed locally, wires the graph, frees VRAM, and runs the render. Watch the 76s demo &rarr;

The local-first, agent-native control plane for [ComfyUI](https://github.com/comfyanonymous/ComfyUI). An MCP server plus a live sidebar agent that generates images, video and audio, authors and runs workflows, manages models and custom nodes, and edits your live ComfyUI graph in natural language. Bring whatever model you have: **Claude or ChatGPT on your subscrip

Read from source at commit 28c3301c636cOBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add comfyui-mcp -- npx -y [email protected]
03

Exposed tools (70)

50 read · 16 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
Clauderead
KJNodesreadUtility nodes
KSamplerread
OtherreadMentions wan in the description only
PuLIDreadIdentity-preserving generation
SAM3readSegment anything
UnrelatedreadNothing matches
WanVideoWrapperreadWan Video diffusion nodes
apply_manifestwriteApply a ComfyUI setup manifest from an inline object or .json/.yaml/.yml file. Composes custom-node installs and model downloads, installs pip packages, and reports apt entries as skipped (system packages need manual/root installation). LOCAL ComfyUI: model downloads use the connected server
appsreadMicro-apps on this ComfyUI (panel Apps feature): named workflows packaged for one-click runs. Driven by the
batchwriteRun MANY ComfyUI workflows under one durable batch_id. Driven by the
bisectreadBinary-search (git-bisect style) over installed ComfyUI custom nodes to find which one causes a problem. A state machine driven by the
calculatereadEvaluate a batch of math expressions exactly — no ComfyUI connection needed, so it works even in cloud mode or when ComfyUI is down. A safe, zero-dependency expression evaluator (no eval): numbers only, no strings/arrays/property access. Handy for the arithmetic agents get wrong token-by-token.\n\n
call_toolwriteRun.
clear_vramdestructiveFree GPU VRAM by unloading cached models from ComfyUI. Use this between generation runs with different model families (e.g. switching from SDXL to Flux) or when running low on VRAM. Optionally unload only models or only memory.
comfy_clireadDrive the official comfy-cli (envelope/1 JSON contract) for the selected ComfyUI environment. The MCP resolves
create_workflowwriteAuthor and check ComfyUI workflow JSON. Driven by the
describe_toolreadDescribe.
download_modelreadModels.
echoreadEcho a string.
enqueue_workflowwriteSubmit work to the ComfyUI execution queue — the primary way an agent starts a render. Driven by the
evil_via_bridgeread
evil_via_callread
fake_generatereadd
generate_imagereadGenerate media from a prompt or an existing image — the high-level entry points that build the graph for you. Every action enqueues on the connected ComfyUI and returns the prompt_id immediately; the resulting asset_id arrives in the completion notification. Driven by the
get_defaultswriteRead and write settings — either OUR generation defaults or ComfyUI
get_historyreadRead what has already been generated on this machine — execution history, why a run failed, and the settings your past renders actually used. Driven by the
get_imagereadFetch, browse and inspect ComfyUI images and registered assets. Driven by the
get_queuereadx
get_system_statsreadStats.
get_workflowreadReturn, list, summarize or query a SAVED workflow FILE — files on disk, named from the library or given as a path/JSON — NOT the graph open on the user
install_comfyuiwriteInstall, update and configure the local ComfyUI installation, its sidebar panel, and this MCP server itself. Driven by the
install_custom_nodedestructiveInstall, repair, enable/disable and remove ComfyUI custom node packs on this ComfyUI. To FIND a pack in the public registry first, use search_custom_nodes. Driven by the
kitchenreadSee what comfy-kitchen can do on this GPU, find where a graph is leaving it on the table, and apply the faster path. Driven by
list_api_nodesread
list_local_modelsreadInspect what models this ComfyUI has installed, and where it looks for them. Driven by the
list_packsreadBundled ComfyUI knowledge — installer packs, model-family skills, workflow templates — plus the two workflow-readiness checks. Driven by the
list_toolsreadCatalog.
model_metadatareadCurate a model file
mypackreadd
nread
node_packread
node_snapshotreadCustom-node snapshots via ComfyUI-Manager (mirrors
noopreadnoop
preadhas
panel_askreadAsk the user to choose.
panel_call_toolwriteRun a panel tool by name with args matching its panel_describe_tool schema.
panel_cleardestructiveClear the graph.
panel_describe_toolreadFull description and JSON Schema for one panel tool.
panel_focus_nodereadFocus a node in the canvas. Long detail here.
panel_list_toolsreadList the live-canvas panel tools (the user
panel_runwriteRun.
panel_set_widgetwriteSet a widget value.
panel_takes_parametersreadA tool whose own schema has a parameters field.
parkedreadRegistered but switched off.
pingreadReturns pong
queuereadInspect and manage the ComfyUI execution queue. Driven by the
report_issuereadARCHIVED — this project is no longer maintained and its issue trackers are closed. This tool files NOTHING and contacts no service: it returns a notice pointing at ComfyUI
restart_comfyuiwriteControl the lifecycle of the ComfyUI server process. Driven by the
runpodwriteDeploy, start, stop, inspect and connect to RunPod cloud GPU pods, and switch rendering between your local machine and a pod. Driven by the
runpod_watchreadWatch a RunPod pod
save_workflowwriteWRITE to the ComfyUI user library: persist a workflow, or capture/verify its provenance lock. This is the only tool here that writes — reading is get_workflow. Driven by the
search_custom_nodesreadDiscover ComfyUI custom node PACKS in the public ComfyUI Registry (registry.comfy.org). Read-only and network-only: queries the hosted registry over HTTP and does NOT require a running ComfyUI or COMFYUI_PATH. This searches node PACKS, not models (use download_model action:\
train_doctorwritePreflight and set up the TRAINER ITSELF — the docker/GPU/venv machinery every training job needs. Touches no dataset and no job. Driven by the
train_prepare_datasetwriteStage and curate the training DATASETS a LoRA run consumes — the images and their captions. Datasets are keyed by
train_startdestructiveRun and inspect LoRA training JOBS — launch a run, poll it, stop it, delete it, and read back the settings behind it. Jobs are keyed by
upload_imagewritePut a file where ComfyUI (or cloud storage) can read it. Driven by the
visualize_workflowreadDRAW a diagram of, or convert, workflow JSON you PASS IN (a JSON string or object) — it does NOT read the user
workspacereadInspect and manage ComfyUI workspaces (local installs). Driven by the
xread
04

Trust audit

BLOCKgrade F · trust 25/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (11 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/orchestrator/index.ts:1476
`Install cloudflared (npm i -g cloudflared), or re-run with --insecure-bridge and open the pod through an ` +
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/orchestrator/index.ts:7070
`Install cloudflared (npm i -g cloudflared), or re-run with --insecure-bridge and open the pod through an ` +
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
plugin/skills/ai-toolkit-trainer/SKILL.md:137
- **RunPod UI won't load / asks for a password.** Confirm `AI_TOOLKIT_AUTH` is set and you're on the 8675 proxy URL.
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/fa/index.mdx:3
description: "سطح کنترلِ محلیمحور و بومیِ عامل برای ComfyUI — یک سرور MCP بههمراه افزونهٔ Claude Code که با زبان طبیعی تصویر، ویدیو و صدا تولید میکند، گردشکار مینویسد و اجرا میکند، و مدلها و گرههای سف
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/fa/index.mdx:8
**این پروژه دیگر نگهداری نمیشود.** ComfyUI اکنون ابزارهای رسمی عامل و MCP — **Comfy Agent** و **Comfy MCP** — را ارائه میدهد که توسط تیم Comfy-Org ساخته و پشتیبانی میشوند، با یکپارچگی عمیقتر از آنچه ی
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/fa/index.mdx:13
**ComfyUI MCP** همان **سطح کنترلِ محلیمحور و بومیِ عامل** برای
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/fa/index.mdx:16
در حال اجرای ComfyUI وصل میکند — **محلی**، **از راه دور**، یا
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/fa/index.mdx:17
**[Comfy Cloud](https://cloud.comfy.org)** — تا بتوانید تصویر، ویدیو و صدا تولید کنید، گردشکارها را
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/orchestrator/grok-backend.ts:1628
logger.warn(`[grok-backend] direct-token turn failed: ${msgOf(err)}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/orchestrator/index.ts:5115
logger.info(`[panel-orchestrator] secret set from panel Settings: ${key} (redacted)`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/services/ui-bridge.ts:3111
logger.info(`[ui-bridge] pairing listener on ws://${host}:${port} (token-gated)`);
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
packs/wan-animate/workflow.json:4748
"/9j/4AAQSkZJRgABAQAAAQABAAD/2wBDAAgGBgcGBQgHBwcJCQgKDBQNDAsLDBkSEw8UHRofHh0aHBwgJC4nICIsIxwcKDcpLDAxNDQ0Hyc5PTgyPC4zNDL/2wBDAQkJCQwLDBgNDRgyIRwhMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjI
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/sync-agents.mjs:20
const normalized = content.replace(/^/, '').replace(/\r\n/g, '\n');
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
src/__tests__/services/respawn-orphans-downloads.test.ts:96
{ filename: "AKIAABCDEFGHIJKLMNOP.safetensors", status: "downloading", trayId: "a" },
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/__tests__/comfyui/enqueue-error-redaction.test.ts:15
const TOKEN = "sk-live-9f2b7c41aa6e4d0e8b3f5a1c2d7e9f04";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/__tests__/comfyui/json-guard-base-url-redaction.test.ts:21
const { TOKEN } = vi.hoisted(() => ({ TOKEN: "AbCdEf0123456789AbCdEf0123456789" }));
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/__tests__/comfyui/json-guard.test.ts:746
const token = "sk-live-9f3aQ2xR7pLmZ0vTbN4wYc8KdE1uHj6S";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/__tests__/comfyui/log-overredaction.test.ts:146
const token = "AbcD3fGh.IjKl9mNo.PqRs7tUv.WxYz2aBc";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/__tests__/comfyui/log-overredaction.test.ts:158
const token = "ABCDEFGHIJKLMNOPQRS/TUVWXYZabcdefghijklm";
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
src/__tests__/services/manager-error-body.test.ts:164
"ghp_ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ";
MEDIUMSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
plugin/skills/local-llm-free/SKILL.md:25
(macOS/Windows installers, or `curl -fsSL https://ollama.com/install.sh | sh` on Linux).
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_vram, install_custom_node, panel_clear, train_start
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.suspicious_name · CWE-1104
src/__tests__/orchestrator/ollama-image-payload-budget.test.ts
ollama-image-payload-budget.test.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWInventory / provenance · inv.suspicious_name · CWE-1104
src/__tests__/services/remote-payload-probe.test.ts
remote-payload-probe.test.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/__tests__/orchestrator/panel-console-http.test.ts:196
for (const body of scripts) expect(() => new Function(body)).not.toThrow();
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha 28c3301c636cfull audit observations/trust-audit/mcp-server/artokun__comfyui-9.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-3028c3301c636cBLOCKF25first audit
06

Questions

What is the ComfyUI MCP server?

Local-first, agent-native control plane for ComfyUI — MCP server + sidebar agent that generates images, video & audio, authors and runs workflows, and edits your live graph in natural language on ANY LLM (Claude, ChatGPT, Gemini, offline Ollama, or any hosted model). 178 tools, 36 AI skills, 55 inst

What tools does ComfyUI expose?

70 in total: 50 read-only, 16 that write, and 4 that can delete or overwrite (clear_vram, install_custom_node, panel_clear, train_start). Every one is listed on this page with its risk.

Is ComfyUI safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (25/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does ComfyUI need?

It reads ANTHROPIC_API_KEY, ATLASCLOUD_API_KEY, AWS_ACCESS_KEY_ID, AWS_CONTAINER_CREDENTIALS_FULL_URI, AWS_CONTAINER_CREDENTIALS_RELATIVE_URI, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, AWS_SHARED_CREDENTIALS_FILE, AWS_WEB_IDENTITY_TOKEN_FILE, AZURE_STORAGE_KEY, BAILIAN_CODING_PLAN_API_KEY and CF_ACCESS_CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does ComfyUI run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as comfyui-mcp at 0.52.203.

How current is this page?

The grade is for one exact copy of the source (28c3301c636c), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement