Comfy CozyBLOCK
Say 'dreamier' and your ComfyUI workflow shifts — instantly, reversibly. An AI co-pilot for VFX artists: zero-LLM recipes (dreamier/sharper/faster), 133 MCP tools, EXR-aware vision, workflow.lock provenance, full undo, native sidebar, 5 swappable brains (Claude, GPT, Gemini, Ollama, Nemotron).
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Patent Pending | MIT License | Patent Details
The production-grade local counterpart to Comfy Cloud MCP — your GPU, your models, reversible, provable.
Talk to ComfyUI like a colleague. It talks back.
- Local execution — renders on your GPU, against your models, on your disk
- Surgical, validated edits — small reversible changes, never rewrites; every edit is one
undoaway - Zero-LLM recipes — "dreamier", "sharper", "faster" apply as instant, deterministic macros
- Provenance —
workflow.lockpins model SHA-256s + pack commits; drift warns at validate - 6 swappable LLM brains — Claude, GPT-4o, Gemini, Ollama, NVIDIA Nemotron, or any OpenAI-compatible endpoint
TL;DR (each line stands alone — take what you need) - Plain-English co-pilot for ComfyUI. You describe the change; the agent does it. - 134 MCP tools · 6 LLM providers — Claude, GPT-4o, Gemini, Ollama, NVIDIA Nemotron, or any OpenAI-compatible endpoint (custom). Swap with one env var or mid-session — your pick sticks across restarts, and it won't switch you to a model that can't run the tools. - Zero-LLM recipes. "Dreamier", "sharper", "faster" — common intents apply as instant, deterministic parameter macros. No API call, no wait, fully undoable. - Keyless run reports. Every render leaves a structured report — env fingerprint, per-node timings, and an explained finding for every anomaly.agent diagnose --last. No API key in that path, ever. - Everything is undoable. Reversible delta layers (LIVRPS), full undo stack, nothing destructive without your say-so. - It learns you. ~30 runs in, it starts biasing toward what actually worked for your renders. C
942b28d9224bOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add comfy-cozy-panel --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env CIVITAI_API_KEY=${CIVITAI_API_KEY} --env CUSTOM_API_KEY=${CUSTOM_API_KEY} --env GEMINI_API_KEY=${GEMINI_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"comfy-cozy-panel": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"CIVITAI_API_KEY": "${CIVITAI_API_KEY}",
"CUSTOM_API_KEY": "${CUSTOM_API_KEY}",
"GEMINI_API_KEY": "${GEMINI_API_KEY}"
}
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
cozy-improve | read | Self-improvement harness: port a verified architectural improvement into Comfy-Cozy as one ratcheted, human-mergeable branch. |
refinement-pass | read | One constitution-governed refinement pass: 3 scout lenses -> adjudicate -> disjoint forge -> crucible. Loop <=3x with commits between passes. |
Trust audit
BLOCKgrade F · trust 59/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
cat > config/bridge.env << 'ENVEOF'
importlib.import_module(f".{_bmod}", package=__name__)_MODULES.append(importlib.import_module(f".{_mod_name}", package=__name__))_mod = importlib.import_module(f"..stage.{_mod_name}", package=__name__)with _m.patch.object(__import__(__name__, fromlist=["_fetch_profile"]),
- ComfyUI API at http://127.0.0.1:8188 (sub-millisecond latency)
│ │ │ │ └── ckpt_name: token = "sdxl_base.safetensors"
api_key = "sk-ant-PASTE-YOUR-KEY-HERE"
else __import__(n, *a, **kw)):
import { app } from "../../../scripts/app.js";const { api } = await import("../../../scripts/api.js");} from "../../panel/web/js/_deltaFailures.js";
import { applyTouchedSet } from "../../panel/web/js/_pushApplyTouched.js";import { withObserverPause } from "../../panel/web/js/_pushControl.js";result = _validate_download_url("https://metadata.google.internal/computeMetadata/v1/")result = _validate_download_url("https://169.254.169.254/latest/meta-data/")lambda host, port, **kw: [(None, None, None, None, ("169.254.169.254", 0))],ComfyUI should be running at: http://127.0.0.1:8188
2. Polls `http://127.0.0.1:8188/system_stats` every 2s until ready
2. Wait until it's loaded (you can see the web UI at `http://127.0.0.1:8188`)
**Fix:** Start ComfyUI first. Verify you can open `http://127.0.0.1:8188` in a browser. If your ComfyUI uses a different port, set `COMFYUI_PORT` in your `.env` file.
data=base64.b64decode(block.data),
sent = Image.open(io.BytesIO(base64.b64decode(data)))
decoded = base64.b64decode(data)
sent = Image.open(io.BytesIO(base64.b64decode(data)))
Gates applied: no_behavioural_pass.
942b28d9224bfull audit observations/trust-audit/mcp-server/josephoibrahim__comfy-cozy.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 942b28d9224b | BLOCK | F | 59 | first audit |
Questions
What is the Comfy Cozy MCP server?
Say 'dreamier' and your ComfyUI workflow shifts — instantly, reversibly. An AI co-pilot for VFX artists: zero-LLM recipes (dreamier/sharper/faster), 133 MCP tools, EXR-aware vision, workflow.lock provenance, full undo, native sidebar, 5 swappable brains (Claude, GPT, Gemini, Ollama, Nemotron).
What tools does Comfy Cozy expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Comfy Cozy safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (59/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Comfy Cozy need?
It reads ANTHROPIC_API_KEY, CIVITAI_API_KEY, CUSTOM_API_KEY, GEMINI_API_KEY, GITHUB_API_TOKEN, GOOGLE_API_KEY, HF_TOKEN, MCP_AUTH_TOKEN, NVIDIA_API_KEY, OPENAI_API_KEY and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Comfy Cozy run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as comfy-cozy-panel at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (942b28d9224b), read on 2026-10-09. The repository is watched and re-audited when it changes.