ComfyUISAFE
lightweight Python-based MCP (Model Context Protocol) server for local ComfyUI
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Generate and refine AI images/audio/video through natural conversation
A lightweight MCP (Model Context Protocol) server that lets AI agents generate and iteratively refine images, audio, and video using a local ComfyUI instance.
You run the server, connect a client, and issue tool calls. Everything else is optional depth.
Quick Start (2–3 minutes)
This proves everything is working.
1) Clone and set up
git clone https://github.com/joenorton/comfyui-mcp-server.git cd comfyui-mcp-server pip install -r requirements.txt
2) Start ComfyUI
Make sure ComfyUI is installed and running locally.
cd python main.py --port 8188
3) Run the MCP server
From the repository directory:
python server.py
The server listens at:
http://127.0.0.1:9000/mcp
4) Verify it works (no AI client required)
Run the included test client:
# Use default prompt python test_client.py # Or provide your own prompt python test_client.py -p "a beautiful sunset over mountains" python test_client.py --prompt "a cat on a mat"
test_client.py will:
- connect to the MCP server
- list available tools
- fetch and display server defaults (width, height, steps, model, etc.)
- run
generate_imagewith your prompt (or a default) - automatically use server defaults for all other parameters
- print the resulting asset information
If this step succeeds, the system is working.
Note: The test client respects server defaults configured via config files, environment variables, or set_defaults calls. Only the prompt parameter is required; all other parameters use server defaults automatically.
That’s it.
Use with an AI Agent (Cursor / Claude / n8n)
Once the server is running, you can connect it to an AI client.
Create a project-scoped .mcp.json file:
{
"mcpServers": {
"comfyui-mcp-server": {
"type": "streamable-http",
"url": "http://127.0.0.dad6fec19f4eOBSERVED · 2026-10-01Exposed tools (15)
10 read · 5 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
cancel_job | read | Cancel a queued or running job. |
get_asset_metadata | read | Get full metadata and provenance for a generated asset. |
get_defaults | read | Get current effective defaults for image, audio, and video generation. |
get_job | read | Get job status and history for a specific prompt ID. |
get_publish_info | write | Get publish configuration and status information. |
get_queue_status | read | Get the current ComfyUI queue status. |
list_assets | read | List recently generated assets for AI memory and browsing. |
list_models | read | List all available checkpoint models in ComfyUI. |
list_workflows | read | List all available workflows in the workflow directory. |
publish_asset | write | Publish a ComfyUI-generated asset to a web project directory. |
regenerate | read | Regenerate an existing asset with optional parameter overrides. |
run_workflow | write | Run a saved ComfyUI workflow with constrained parameter overrides. |
set_comfyui_output_root | write | Set ComfyUI output root directory in persistent configuration. |
set_defaults | write | Set runtime defaults for image, audio, and/or video generation. |
view_image | read | View a generated image inline in chat (thumbnail preview only). |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
manager.resolve_source_path(subfolder="../../outside", filename="test.png")
manager.resolve_source_path(subfolder="../../outside", filename="malicious.png")
http://127.0.0.1:9000/mcp
"url": "http://127.0.0.1:9000/mcp"
- Verify server shows "Server running at http://127.0.0.1:9000/mcp" in the console
- Test server directly: `curl http://127.0.0.1:9000/mcp` (should return MCP response)
"url": "http://127.0.0.1:9000/mcp"
requests, mcp, Pillow, pytest
Gates applied: no_behavioural_pass.
dad6fec19f4efull audit observations/trust-audit/mcp-server/joenorton__comfyui.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-01 | dad6fec19f4e | SAFE | B | 89 | first audit |
Questions
What is the ComfyUI MCP server?
lightweight Python-based MCP (Model Context Protocol) server for local ComfyUI
What tools does ComfyUI expose?
15 in total: 10 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is ComfyUI safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does ComfyUI need?
No credential environment variables were found in its source, so it appears to need none.
How does ComfyUI run?
It speaks stdio and streamable-http, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (dad6fec19f4e), read on 2026-10-01. The repository is watched and re-audited when it changes.