ComfyUIBLOCK
Local-first, agent-native control plane for ComfyUI — MCP server + sidebar agent that generates images, video & audio, authors and runs workflows, and edits your live graph in natural language on ANY LLM (Claude, ChatGPT, Gemini, offline Ollama, or any hosted model). 178 tools, 36 AI skills, 55 inst
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[!IMPORTANT] This project is no longer maintained. ComfyUI now ships official agent and MCP tooling — [Comfy Agent](https://comfy.org/agent) and [Comfy MCP](https://comfy.org/mcp) — built and supported by the Comfy-Org team with deeper integration than a community project can match. If you’re looking for an MCP server or AI agent for ComfyUI, use the official tooling. This repo will remain public as a reference, but no new features, bug fixes, or dependency updates will be made. Issues and pull requests close when the repo is archived on 2026-10-09. The community Discord goes read-only the same day, with its threads left up as a searchable archive. Thanks to everyone who used, starred, forked, and contributed to this project. It was a good run. :rocket: The full story is in the goodbye post. Looking for a ComfyUI or generative-AI integration expert? I take on custom solutions — reach me by email at [email protected] or on LinkedIn.
<img src="docs/images/demo-poster.jpg" width="760" alt="The Agent panel driving ComfyUI end to end. Click to watch the demo">
The Agent panel driving ComfyUI end to end. It reads what is installed locally, wires the graph, frees VRAM, and runs the render. Watch the 76s demo →
The local-first, agent-native control plane for [ComfyUI](https://github.com/comfyanonymous/ComfyUI). An MCP server plus a live sidebar agent that generates images, video and audio, authors and runs workflows, manages models and custom nodes, and edits your live ComfyUI graph in natural language. Bring whatever model you have: **Claude or ChatGPT on your subscrip
28c3301c636cOBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add comfyui-mcp -- npx -y [email protected]
Exposed tools (70)
50 read · 16 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Claude | read | |
KJNodes | read | Utility nodes |
KSampler | read | |
Other | read | Mentions wan in the description only |
PuLID | read | Identity-preserving generation |
SAM3 | read | Segment anything |
Unrelated | read | Nothing matches |
WanVideoWrapper | read | Wan Video diffusion nodes |
apply_manifest | write | Apply a ComfyUI setup manifest from an inline object or .json/.yaml/.yml file. Composes custom-node installs and model downloads, installs pip packages, and reports apt entries as skipped (system packages need manual/root installation). LOCAL ComfyUI: model downloads use the connected server |
apps | read | Micro-apps on this ComfyUI (panel Apps feature): named workflows packaged for one-click runs. Driven by the |
batch | write | Run MANY ComfyUI workflows under one durable batch_id. Driven by the |
bisect | read | Binary-search (git-bisect style) over installed ComfyUI custom nodes to find which one causes a problem. A state machine driven by the |
calculate | read | Evaluate a batch of math expressions exactly — no ComfyUI connection needed, so it works even in cloud mode or when ComfyUI is down. A safe, zero-dependency expression evaluator (no eval): numbers only, no strings/arrays/property access. Handy for the arithmetic agents get wrong token-by-token.\n\n |
call_tool | write | Run. |
clear_vram | destructive | Free GPU VRAM by unloading cached models from ComfyUI. Use this between generation runs with different model families (e.g. switching from SDXL to Flux) or when running low on VRAM. Optionally unload only models or only memory. |
comfy_cli | read | Drive the official comfy-cli (envelope/1 JSON contract) for the selected ComfyUI environment. The MCP resolves |
create_workflow | write | Author and check ComfyUI workflow JSON. Driven by the |
describe_tool | read | Describe. |
download_model | read | Models. |
echo | read | Echo a string. |
enqueue_workflow | write | Submit work to the ComfyUI execution queue — the primary way an agent starts a render. Driven by the |
evil_via_bridge | read | |
evil_via_call | read | |
fake_generate | read | d |
generate_image | read | Generate media from a prompt or an existing image — the high-level entry points that build the graph for you. Every action enqueues on the connected ComfyUI and returns the prompt_id immediately; the resulting asset_id arrives in the completion notification. Driven by the |
get_defaults | write | Read and write settings — either OUR generation defaults or ComfyUI |
get_history | read | Read what has already been generated on this machine — execution history, why a run failed, and the settings your past renders actually used. Driven by the |
get_image | read | Fetch, browse and inspect ComfyUI images and registered assets. Driven by the |
get_queue | read | x |
get_system_stats | read | Stats. |
get_workflow | read | Return, list, summarize or query a SAVED workflow FILE — files on disk, named from the library or given as a path/JSON — NOT the graph open on the user |
install_comfyui | write | Install, update and configure the local ComfyUI installation, its sidebar panel, and this MCP server itself. Driven by the |
install_custom_node | destructive | Install, repair, enable/disable and remove ComfyUI custom node packs on this ComfyUI. To FIND a pack in the public registry first, use search_custom_nodes. Driven by the |
kitchen | read | See what comfy-kitchen can do on this GPU, find where a graph is leaving it on the table, and apply the faster path. Driven by |
list_api_nodes | read | |
list_local_models | read | Inspect what models this ComfyUI has installed, and where it looks for them. Driven by the |
list_packs | read | Bundled ComfyUI knowledge — installer packs, model-family skills, workflow templates — plus the two workflow-readiness checks. Driven by the |
list_tools | read | Catalog. |
model_metadata | read | Curate a model file |
mypack | read | d |
n | read | |
node_pack | read | |
node_snapshot | read | Custom-node snapshots via ComfyUI-Manager (mirrors |
noop | read | noop |
p | read | has |
panel_ask | read | Ask the user to choose. |
panel_call_tool | write | Run a panel tool by name with args matching its panel_describe_tool schema. |
panel_clear | destructive | Clear the graph. |
panel_describe_tool | read | Full description and JSON Schema for one panel tool. |
panel_focus_node | read | Focus a node in the canvas. Long detail here. |
panel_list_tools | read | List the live-canvas panel tools (the user |
panel_run | write | Run. |
panel_set_widget | write | Set a widget value. |
panel_takes_parameters | read | A tool whose own schema has a parameters field. |
parked | read | Registered but switched off. |
ping | read | Returns pong |
queue | read | Inspect and manage the ComfyUI execution queue. Driven by the |
report_issue | read | ARCHIVED — this project is no longer maintained and its issue trackers are closed. This tool files NOTHING and contacts no service: it returns a notice pointing at ComfyUI |
restart_comfyui | write | Control the lifecycle of the ComfyUI server process. Driven by the |
runpod | write | Deploy, start, stop, inspect and connect to RunPod cloud GPU pods, and switch rendering between your local machine and a pod. Driven by the |
runpod_watch | read | Watch a RunPod pod |
save_workflow | write | WRITE to the ComfyUI user library: persist a workflow, or capture/verify its provenance lock. This is the only tool here that writes — reading is get_workflow. Driven by the |
search_custom_nodes | read | Discover ComfyUI custom node PACKS in the public ComfyUI Registry (registry.comfy.org). Read-only and network-only: queries the hosted registry over HTTP and does NOT require a running ComfyUI or COMFYUI_PATH. This searches node PACKS, not models (use download_model action:\ |
train_doctor | write | Preflight and set up the TRAINER ITSELF — the docker/GPU/venv machinery every training job needs. Touches no dataset and no job. Driven by the |
train_prepare_dataset | write | Stage and curate the training DATASETS a LoRA run consumes — the images and their captions. Datasets are keyed by |
train_start | destructive | Run and inspect LoRA training JOBS — launch a run, poll it, stop it, delete it, and read back the settings behind it. Jobs are keyed by |
upload_image | write | Put a file where ComfyUI (or cloud storage) can read it. Driven by the |
visualize_workflow | read | DRAW a diagram of, or convert, workflow JSON you PASS IN (a JSON string or object) — it does NOT read the user |
workspace | read | Inspect and manage ComfyUI workspaces (local installs). Driven by the |
x | read |
Trust audit
BLOCKgrade F · trust 25/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (11 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
`Install cloudflared (npm i -g cloudflared), or re-run with --insecure-bridge and open the pod through an ` +
`Install cloudflared (npm i -g cloudflared), or re-run with --insecure-bridge and open the pod through an ` +
- **RunPod UI won't load / asks for a password.** Confirm `AI_TOOLKIT_AUTH` is set and you're on the 8675 proxy URL.
description: "سطح کنترلِ محلیمحور و بومیِ عامل برای ComfyUI — یک سرور MCP بههمراه افزونهٔ Claude Code که با زبان طبیعی تصویر، ویدیو و صدا تولید میکند، گردشکار مینویسد و اجرا میکند، و مدلها و گرههای سف
**این پروژه دیگر نگهداری نمیشود.** ComfyUI اکنون ابزارهای رسمی عامل و MCP — **Comfy Agent** و **Comfy MCP** — را ارائه میدهد که توسط تیم Comfy-Org ساخته و پشتیبانی میشوند، با یکپارچگی عمیقتر از آنچه ی
**ComfyUI MCP** همان **سطح کنترلِ محلیمحور و بومیِ عامل** برای
در حال اجرای ComfyUI وصل میکند — **محلی**، **از راه دور**، یا
**[Comfy Cloud](https://cloud.comfy.org)** — تا بتوانید تصویر، ویدیو و صدا تولید کنید، گردشکارها را
logger.warn(`[grok-backend] direct-token turn failed: ${msgOf(err)}`);logger.info(`[panel-orchestrator] secret set from panel Settings: ${key} (redacted)`);logger.info(`[ui-bridge] pairing listener on ws://${host}:${port} (token-gated)`);"/9j/4AAQSkZJRgABAQAAAQABAAD/2wBDAAgGBgcGBQgHBwcJCQgKDBQNDAsLDBkSEw8UHRofHh0aHBwgJC4nICIsIxwcKDcpLDAxNDQ0Hyc5PTgyPC4zNDL/2wBDAQkJCQwLDBgNDRgyIRwhMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjI
const normalized = content.replace(/^/, '').replace(/\r\n/g, '\n');
{ filename: "AKIAABCDEFGHIJKLMNOP.safetensors", status: "downloading", trayId: "a" },const TOKEN = "sk-live-9f2b7c41aa6e4d0e8b3f5a1c2d7e9f04";
const { TOKEN } = vi.hoisted(() => ({ TOKEN: "AbCdEf0123456789AbCdEf0123456789" }));const token = "sk-live-9f3aQ2xR7pLmZ0vTbN4wYc8KdE1uHj6S";
const token = "AbcD3fGh.IjKl9mNo.PqRs7tUv.WxYz2aBc";
const token = "ABCDEFGHIJKLMNOPQRS/TUVWXYZabcdefghijklm";
"ghp_ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ";
(macOS/Windows installers, or `curl -fsSL https://ollama.com/install.sh | sh` on Linux).
clear_vram, install_custom_node, panel_clear, train_start
ollama-image-payload-budget.test.ts
remote-payload-probe.test.ts
for (const body of scripts) expect(() => new Function(body)).not.toThrow();
Gates applied: no_behavioural_pass.
28c3301c636cfull audit observations/trust-audit/mcp-server/artokun__comfyui-9.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | 28c3301c636c | BLOCK | F | 25 | first audit |
Questions
What is the ComfyUI MCP server?
Local-first, agent-native control plane for ComfyUI — MCP server + sidebar agent that generates images, video & audio, authors and runs workflows, and edits your live graph in natural language on ANY LLM (Claude, ChatGPT, Gemini, offline Ollama, or any hosted model). 178 tools, 36 AI skills, 55 inst
What tools does ComfyUI expose?
70 in total: 50 read-only, 16 that write, and 4 that can delete or overwrite (clear_vram, install_custom_node, panel_clear, train_start). Every one is listed on this page with its risk.
Is ComfyUI safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (25/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does ComfyUI need?
It reads ANTHROPIC_API_KEY, ATLASCLOUD_API_KEY, AWS_ACCESS_KEY_ID, AWS_CONTAINER_CREDENTIALS_FULL_URI, AWS_CONTAINER_CREDENTIALS_RELATIVE_URI, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, AWS_SHARED_CREDENTIALS_FILE, AWS_WEB_IDENTITY_TOKEN_FILE, AZURE_STORAGE_KEY, BAILIAN_CODING_PLAN_API_KEY and CF_ACCESS_CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does ComfyUI run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as comfyui-mcp at 0.52.203.
How current is this page?
The grade is for one exact copy of the source (28c3301c636c), read on 2026-09-30. The repository is watched and re-audited when it changes.