← Back to search

comfyui-mcp

GitHub Actions Scanned 26d ago

Local-first, agent-native control plane for ComfyUI — MCP server + autonomous sidebar agent that drives your live graph in natural language on ANY LLM: Claude/ChatGPT/Gemini on your subscription (no API key), free local models via Ollama (fully offline)

D
40 / 100

Versions

0.48.21latest
Jul 30, 2026
0.48.20
Jul 30, 2026
0.48.19
Jul 30, 2026
0.48.18
Jul 30, 2026
0.48.17
Jul 30, 2026
+ show 114 moreshow less
0.48.16
Jul 30, 2026
0.48.15
Jul 30, 2026
0.48.14
Jul 30, 2026
0.48.13
Jul 30, 2026
0.48.12
Jul 30, 2026
0.48.11
Jul 30, 2026
0.48.10
Jul 30, 2026
0.48.9
Jul 30, 2026
0.48.8
Jul 30, 2026
0.48.7
Jul 30, 2026
0.48.6
Jul 29, 2026
0.48.5
Jul 28, 2026
0.48.4
Jul 28, 2026
0.48.3
Jul 28, 2026
0.48.2
Jul 27, 2026
0.48.1
Jul 26, 2026
0.48.0
Jul 24, 2026
0.47.0
Jul 23, 2026
0.46.0
Jul 22, 2026
0.45.0
Jul 22, 2026
0.44.0
Jul 21, 2026
0.43.1
Jul 21, 2026
0.43.0
Jul 21, 2026
0.42.0
Jul 21, 2026
0.41.0
Jul 20, 2026
0.40.0
Jul 20, 2026
0.39.0
Jul 19, 2026
0.38.1
Jul 18, 2026
0.38.0
Jul 18, 2026
0.37.0
Jul 17, 2026
0.36.0
Jul 16, 2026
0.35.0
Jul 16, 2026
0.34.0
Jul 15, 2026
0.33.0
Jul 15, 2026
0.32.0
Jul 14, 2026
0.31.1
Jul 14, 2026
0.31.0
Jul 13, 2026
0.30.0
Jul 10, 2026
0.29.0
Jul 10, 2026
0.28.0
Jul 9, 2026
0.27.0
Jul 9, 2026
0.26.5
Jul 9, 2026
0.26.4
Jul 8, 2026
0.26.3
Jul 8, 2026
0.26.2
Jul 8, 2026
0.26.1
Jul 8, 2026
0.26.0
Jul 7, 2026
0.25.2
Jul 7, 2026
0.25.1
Jul 6, 2026
0.25.0
Jul 6, 2026
0.24.5
Jul 3, 2026
0.24.4
Jul 3, 2026
0.24.3
Jul 3, 2026
0.24.2
Jul 2, 2026
0.24.1
Jul 2, 2026
0.24.0
Jul 2, 2026
0.23.5
Jul 1, 2026
0.23.4
Jul 1, 2026
0.23.3
Jul 1, 2026
0.23.2
Jul 1, 2026
0.23.1
Jul 1, 2026
0.23.0
Jul 1, 2026
0.22.0
Jun 30, 2026
0.21.1
Jun 29, 2026
0.21.0
Jun 29, 2026
0.20.9
Jun 27, 2026
0.20.8
Jun 27, 2026
0.20.7
Jun 27, 2026
0.20.6
Jun 27, 2026
0.20.5
Jun 27, 2026
0.20.4
Jun 27, 2026
0.20.3
Jun 27, 2026
0.20.2
Jun 27, 2026
0.20.1
Jun 26, 2026
0.20.0
Jun 26, 2026
0.19.1
Jun 26, 2026
0.19.0
Jun 26, 2026
0.18.0
Jun 25, 2026
0.17.1
Jun 23, 2026
0.17.0
Jun 22, 2026
0.16.0
Jun 20, 2026
0.15.0
Jun 19, 2026
0.14.0
Jun 17, 2026
0.13.0
Jun 15, 2026
0.12.0
Jun 13, 2026
0.11.1
Jun 12, 2026
0.11.0
Jun 12, 2026
0.10.1
Jun 12, 2026
0.10.0
Jun 11, 2026
0.9.6
Jun 11, 2026
0.9.5
Jun 11, 2026
0.9.4
Jun 3, 2026
0.9.3
Jun 1, 2026
0.9.2
Jun 1, 2026
0.9.1
Jun 1, 2026
0.9.0
Jun 1, 2026
0.8.1
Jun 1, 2026
0.8.0
May 26, 2026
0.7.0
May 26, 2026
0.6.1
May 25, 2026
0.6.0
May 25, 2026
0.5.0
May 21, 2026
0.4.1
May 21, 2026
0.4.0
May 21, 2026
0.3.2
Feb 17, 2026
0.3.1
Feb 17, 2026
0.3.0
Feb 17, 2026
0.2.0
Feb 16, 2026
0.1.5
Feb 15, 2026
0.1.4
Feb 15, 2026
0.1.3
Feb 15, 2026
0.1.2
Feb 15, 2026
0.1.1
Feb 15, 2026
0.1.0
Feb 15, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 50

visualize_workflow
annotations: none low

DRAW a diagram of, or convert, workflow JSON you PASS IN (a JSON string or object) — it does NOT read the user

dsl string
comfyui-panel
annotations: none low

get_system_stats
annotations: none low

Inspect the connected ComfyUI server: what it is running on, what it has logged, and whether it is healthy enough to dispatch work to. All three actions are READ-ONLY — nothing here mutates anything. Driven by the `action` parameter:\n

enqueue_workflow
annotations: none low

Submit work to the ComfyUI execution queue — the primary way an agent starts a render. Driven by the `action` parameter:\n

install_custom_node
annotations: none low

Install, repair, enable/disable and remove ComfyUI custom node packs on this ComfyUI. To FIND a pack in the public registry first, use search_custom_nodes. Driven by the `action` parameter:\n

search_custom_nodes
annotations: none low

Discover ComfyUI custom node PACKS in the public ComfyUI Registry (registry.comfy.org). Read-only and network-only: queries the hosted registry over HTTP and does NOT require a running ComfyUI or COMFYUI_PATH. This searches node PACKS, not models (use download_model action:\

apply_manifest
annotations: none low

Apply a ComfyUI setup manifest from an inline object or .json/.yaml/.yml file. Composes custom-node installs and model downloads, installs pip packages, and reports apt entries as skipped (system packages need manual/root installation). LOCAL ComfyUI: model downloads use the connected server

download_model
annotations: none low

Find model weights and get them onto the connected ComfyUI, and track the transfers. Driven by the `action` parameter:\n

list_local_models
annotations: none low

Inspect what models this ComfyUI has installed, and where it looks for them. Driven by the `action` parameter:\n

comfy_cli
annotations: none low

Drive the official comfy-cli (envelope/1 JSON contract) for the selected ComfyUI environment. The MCP resolves `comfy` from COMFY_CLI_PATH, PATH, or the selected workspace

all boolean url string name string path string text string type string wait boolean apply boolean limit number query string folder string outDir string urlOnly boolean promptId string overwrite boolean projectDir string relativePath string workflowPath string objectInfoPath string timeoutSeconds number
list_packs
annotations: none low

Bundled ComfyUI knowledge — installer packs, model-family skills, workflow templates — plus the two workflow-readiness checks. Driven by the `action` parameter:\n

train_prepare_dataset
annotations: none low

Stage and curate the training DATASETS a LoRA run consumes — the images and their captions. Datasets are keyed by `name`; the jobs that train on them live in the separate `train_start` tool and are keyed by `id`. Driven by the `action` parameter:\n

path string caption string filename string subfolder string
train_start
annotations: none low

Run and inspect LoRA training JOBS — launch a run, poll it, stop it, delete it, and read back the settings behind it. Jobs are keyed by `id`; the datasets they train on live in the separate `train_prepare_dataset` tool and are keyed by `name`. Driven by the `action` parameter:\n

device string pod_id string trigger string model_path string keep_outputs boolean
train_doctor
annotations: none low

Preflight and set up the TRAINER ITSELF — the docker/GPU/venv machinery every training job needs. Touches no dataset and no job. Driven by the `action` parameter:\n

pod_id string
get_history
annotations: none low

Read what has already been generated on this machine — execution history, why a run failed, and the settings your past renders actually used. Driven by the `action` parameter:\n

list_api_nodes
annotations: none low

Discover and run hosted partner/API nodes on the connected ComfyUI (e.g. Flux/BFL, Ideogram, Kling, Stability). These call external image/video providers and run server-side, requiring a Comfy account/API key configured on the ComfyUI server — they spend PAID api credits, unlike a local-GPU render. Driven by the `action` parameter:\n

clear_vram
annotations: none low

Free GPU VRAM by unloading cached models from ComfyUI. Use this between generation runs with different model families (e.g. switching from SDXL to Flux) or when running low on VRAM. Optionally unload only models or only memory.

report_issue
annotations: none low

File or triage a GitHub issue for a bug/problem you hit (ComfyUI, a workflow, a model, custom nodes, or comfyui-mcp/its panel). For OUR repos (artokun/comfyui-mcp, artokun/comfyui-mcp-panel) it sends the report to the AI triage worker, which searches existing OPEN and CLOSED issues, version-matches, and either files a new issue, adds context to an existing one, or — if the problem was already FIXED in a newer version than the user runs — answers with the fixing PR + fixed-in version and a recommendation to upgrade (no new issue). It returns that triage result plus an instant check of whether the user is on the latest versions. TIMING: this call BLOCKS while the triage runs — typically a few minutes — and that wait is normal, not a hang. It always returns eventually (every request is time-capped and the poll budget is bounded); on a failing network the caps make that wait longer, but never indefinite. Do not abort a slow call just to retry it: once the worker has accepted the report it keeps triaging on its own — filing, deduping into an existing issue, advising an upgrade, or (rarely) reporting that it could not file — so a blind retry can double-file. If triage outlasts the polling budget the call still returns, with pending:true (and a job_id when the worker gave one — an accepted submit whose acknowledgement was unreadable returns pending without it). If the worker is unreachable it falls back to a prefilled GitHub

title string
model_metadata
annotations: none low

Curate a model file

my_model.safetensors
annotations: none low

get_image
annotations: none low

Fetch, browse and inspect ComfyUI images and registered assets. Driven by the `action` parameter:\n

lossless boolean progressive boolean
upload_image
annotations: none low

Put a file where ComfyUI (or cloud storage) can read it. Driven by the `action` parameter:\n

generate_image
annotations: none low

Generate media from a prompt or an existing image — the high-level entry points that build the graph for you. Every action enqueues on the connected ComfyUI and returns the prompt_id immediately; the resulting asset_id arrives in the completion notification. Driven by the `action` parameter:\n

install_comfyui
annotations: none low

Install, update and configure the local ComfyUI installation, its sidebar panel, and this MCP server itself. Driven by the `action` parameter:\n

restart_comfyui
annotations: none low

Control the lifecycle of the ComfyUI server process. Driven by the `action` parameter:\n

workspace
annotations: none low

Inspect and manage ComfyUI workspaces (local installs). Driven by the `action` parameter:\n

node_pack
annotations: none low

Author, edit, test and publish YOUR OWN ComfyUI custom-node pack under <COMFYUI_PATH>/custom_nodes/. LOCAL-ONLY: it acts on the local filesystem and is meaningless for a remote --comfyui-url target. Every file-touching action (list_files, read, search, write, patch, git) is jailed to custom_nodes/ under the resolved local base — the running server

get_defaults
annotations: none low

Read and write settings — either OUR generation defaults or ComfyUI

calculate
annotations: none low

Evaluate a batch of math expressions exactly — no ComfyUI connection needed, so it works even in cloud mode or when ComfyUI is down. A safe, zero-dependency expression evaluator (no eval): numbers only, no strings/arrays/property access. Handy for the arithmetic agents get wrong token-by-token.\n\n

batch
annotations: none low

Run MANY ComfyUI workflows under one durable batch_id. Driven by the `action` parameter:\n

queue
annotations: none low

Inspect and manage the ComfyUI execution queue. Driven by the `action` parameter:\n

get_workflow
annotations: none low

Return, list, summarize or query a SAVED workflow FILE — files on disk, named from the library or given as a path/JSON — NOT the graph open on the user

title string
save_workflow
annotations: none low

WRITE to the ComfyUI user library: persist a workflow, or capture/verify its provenance lock. This is the only tool here that writes — reading is get_workflow. Driven by the `action` parameter:\n

node_snapshot
annotations: none low

Custom-node snapshots via ComfyUI-Manager (mirrors `comfy node save-snapshot` / `restore-snapshot`). Driven by the `action` parameter:\n

create_workflow
annotations: none low

Author and check ComfyUI workflow JSON. Driven by the `action` parameter:\n

runpod
annotations: none low

Deploy, start, stop, inspect and connect to RunPod cloud GPU pods, and switch rendering between your local machine and a pod. Driven by the `action` parameter. SPENDS MONEY: action:\

name string
runpod_watch
annotations: none low

Watch a RunPod pod

apps
annotations: none low

Micro-apps on this ComfyUI (panel Apps feature): named workflows packaged for one-click runs. Driven by the `action` parameter:\n

comfyui-mcp-introspect
annotations: none low

bisect
annotations: none low

Binary-search (git-bisect style) over installed ComfyUI custom nodes to find which one causes a problem. A state machine driven by the `action` parameter:\n

ping
annotations: none low

Returns pong

echo
annotations: none low

Echoes the message

message string
test-client
annotations: none low

parked
annotations: none low

Registered but switched off.

retired-redirect-test-client
annotations: none low

no-tools
annotations: none low

call_tool
annotations: none low

A workflow that happens to be named call_tool.

list_tools
annotations: none low

A workflow squatting list_tools.

test
annotations: none low

c
annotations: none low

Permissions 4

network medium
Server uses network capabilities via: fetch(), http, net, urllib
filesystem low
Server uses filesystem capabilities via: fs, fs sync ops, fs/promises, open(), os, path, pathlib, shutil, tempfile
shell high
Server uses shell capabilities via: child_process, execSync(), spawn(), spawnSync(), subprocess
env_vars low
Server uses env_vars capabilities via: os.environ, process.env

Scan Findings 136

low
Tool 'comfyui-panel' has no annotations annotation_checker · 100%
low
Tool 'get_system_stats' has no annotations annotation_checker · 100%
low
Tool 'enqueue_workflow' has no annotations annotation_checker · 100%
low
Tool 'install_custom_node' has no annotations annotation_checker · 100%
low
Tool 'search_custom_nodes' has no annotations annotation_checker · 100%
low
Tool 'apply_manifest' has no annotations annotation_checker · 100%
low
Tool 'download_model' has no annotations annotation_checker · 100%
low
Tool 'list_local_models' has no annotations annotation_checker · 100%
low
Tool 'comfy_cli' has no annotations annotation_checker · 100%
low
Tool 'list_packs' has no annotations annotation_checker · 100%
low
Tool 'train_prepare_dataset' has no annotations annotation_checker · 100%
low
Tool 'train_start' has no annotations annotation_checker · 100%
low
Tool 'train_doctor' has no annotations annotation_checker · 100%
low
Tool 'visualize_workflow' has no annotations annotation_checker · 100%
low
Tool 'get_history' has no annotations annotation_checker · 100%
low
Tool 'list_api_nodes' has no annotations annotation_checker · 100%
low
Tool 'clear_vram' has no annotations annotation_checker · 100%
low
Tool 'report_issue' has no annotations annotation_checker · 100%
low
Tool 'model_metadata' has no annotations annotation_checker · 100%
low
Tool 'my_model.safetensors' has no annotations annotation_checker · 100%
low
Tool 'get_image' has no annotations annotation_checker · 100%
low
Tool 'upload_image' has no annotations annotation_checker · 100%
low
Tool 'generate_image' has no annotations annotation_checker · 100%
low
Tool 'install_comfyui' has no annotations annotation_checker · 100%
low
Tool 'restart_comfyui' has no annotations annotation_checker · 100%
low
Tool 'workspace' has no annotations annotation_checker · 100%
low
Tool 'node_pack' has no annotations annotation_checker · 100%
low
Tool 'get_defaults' has no annotations annotation_checker · 100%
low
Tool 'calculate' has no annotations annotation_checker · 100%
low
Tool 'batch' has no annotations annotation_checker · 100%
low
Tool 'queue' has no annotations annotation_checker · 100%
low
Tool 'get_workflow' has no annotations annotation_checker · 100%
low
Tool 'save_workflow' has no annotations annotation_checker · 100%
low
Tool 'node_snapshot' has no annotations annotation_checker · 100%
low
Tool 'create_workflow' has no annotations annotation_checker · 100%
low
Tool 'runpod' has no annotations annotation_checker · 100%
low
Tool 'runpod_watch' has no annotations annotation_checker · 100%
low
Tool 'apps' has no annotations annotation_checker · 100%
low
Tool 'comfyui-mcp-introspect' has no annotations annotation_checker · 100%
low
Tool 'bisect' has no annotations annotation_checker · 100%
low
Tool 'ping' has no annotations annotation_checker · 100%
low
Tool 'echo' has no annotations annotation_checker · 100%
low
Tool 'test-client' has no annotations annotation_checker · 100%
low
Tool 'parked' has no annotations annotation_checker · 100%
low
Tool 'retired-redirect-test-client' has no annotations annotation_checker · 100%
low
Tool 'no-tools' has no annotations annotation_checker · 100%
low
Tool 'call_tool' has no annotations annotation_checker · 100%
low
Tool 'list_tools' has no annotations annotation_checker · 100%
low
Tool 'test' has no annotations annotation_checker · 100%
low
Tool 'c' has no annotations annotation_checker · 100%
high
Hardcoded OAuth client ID in artokun-comfyui-mcp-37a0b0c/src/services/oauth-flow.ts auth_checker · 85%
high
Hardcoded OAuth client ID in artokun-comfyui-mcp-37a0b0c/src/services/code-provider-auth.ts auth_checker · 85%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Buffer.from base64 in artokun-comfyui-mcp-37a0b0c/src/orchestrator/index.ts:5412 entropy_analyzer · 75%
medium
Buffer.from base64 in artokun-comfyui-mcp-37a0b0c/src/tools/image-management.ts:407 entropy_analyzer · 75%
medium
Hex string literal (>50 chars) in artokun-comfyui-mcp-37a0b0c/src/tools/vocabulary.ts:123 entropy_analyzer · 70%
medium
Hex string literal (>50 chars) in artokun-comfyui-mcp-37a0b0c/src/tools/vocabulary.ts:172 entropy_analyzer · 70%
medium
Buffer.from base64 in artokun-comfyui-mcp-37a0b0c/src/services/image-convert.ts:207 entropy_analyzer · 75%
medium
Buffer.from base64 in artokun-comfyui-mcp-37a0b0c/src/services/skill-generator.ts:134 entropy_analyzer · 75%
medium
Buffer.from base64 in artokun-comfyui-mcp-37a0b0c/src/services/color-analysis.ts:100 entropy_analyzer · 75%
medium
Buffer.from base64 in artokun-comfyui-mcp-37a0b0c/src/services/color-analysis.ts:109 entropy_analyzer · 75%
medium
Buffer.from base64 in artokun-comfyui-mcp-37a0b0c/src/services/image-management.ts:926 entropy_analyzer · 75%
medium
Buffer.from base64 in artokun-comfyui-mcp-37a0b0c/src/services/image-management.ts:1169 entropy_analyzer · 75%
medium
Buffer.from base64 in artokun-comfyui-mcp-37a0b0c/src/services/inline-preview.ts:156 entropy_analyzer · 75%
medium
Buffer.from base64 in artokun-comfyui-mcp-37a0b0c/src/services/inline-preview.ts:167 entropy_analyzer · 75%
medium
Buffer.from base64 in artokun-comfyui-mcp-37a0b0c/src/services/storage-upload.ts:128 entropy_analyzer · 75%
medium
Buffer.from base64 in artokun-comfyui-mcp-37a0b0c/src/__tests__/tools/get-image-binary-safe.test.ts:129 entropy_analyzer · 75%
info
Tool: runpod_watch manifest_parser · 70%
medium
Hex string literal (>50 chars) in artokun-comfyui-mcp-37a0b0c/src/__tests__/tools/vocabulary-handshake.test.ts:21 entropy_analyzer · 70%
medium
Buffer.from base64 in artokun-comfyui-mcp-37a0b0c/src/__tests__/tools/get-image-save-dir.test.ts:106 entropy_analyzer · 75%
medium
Buffer.from base64 in artokun-comfyui-mcp-37a0b0c/src/__tests__/tools/get-image-save-dir.test.ts:129 entropy_analyzer · 75%
medium
Buffer.from base64 in artokun-comfyui-mcp-37a0b0c/src/__tests__/services/inline-preview.test.ts:35 entropy_analyzer · 75%
medium
Buffer.from base64 in artokun-comfyui-mcp-37a0b0c/src/__tests__/services/training-datasets.test.ts:86 entropy_analyzer · 75%
info
package.json metadata manifest_parser · 100%
info
pyproject.toml metadata manifest_parser · 100%
info
Tool: comfyui-panel manifest_parser · 75%
info
Tool: get_system_stats manifest_parser · 70%
info
Tool: enqueue_workflow manifest_parser · 70%
info
Tool: install_custom_node manifest_parser · 70%
info
Tool: search_custom_nodes manifest_parser · 70%
info
Tool: apply_manifest manifest_parser · 70%
info
Tool: download_model manifest_parser · 70%
info
Tool: list_local_models manifest_parser · 70%
info
Tool: comfy_cli manifest_parser · 70%
info
Tool: list_packs manifest_parser · 70%
info
Tool: train_prepare_dataset manifest_parser · 70%
info
Tool: train_start manifest_parser · 70%
info
Tool: train_doctor manifest_parser · 70%
info
Tool: visualize_workflow manifest_parser · 70%
info
Tool: get_history manifest_parser · 70%
info
Tool: list_api_nodes manifest_parser · 70%
info
Tool: clear_vram manifest_parser · 70%
info
Tool: node_snapshot manifest_parser · 70%
info
Tool: report_issue manifest_parser · 70%
info
Tool: model_metadata manifest_parser · 70%
info
Tool: my_model.safetensors manifest_parser · 75%
info
Tool: get_image manifest_parser · 70%
info
Tool: upload_image manifest_parser · 70%
info
Tool: generate_image manifest_parser · 70%
info
Tool: install_comfyui manifest_parser · 70%
info
Tool: restart_comfyui manifest_parser · 70%
info
Tool: workspace manifest_parser · 70%
info
Tool: node_pack manifest_parser · 70%
info
Tool: get_defaults manifest_parser · 70%
info
Tool: calculate manifest_parser · 70%
info
Tool: batch manifest_parser · 70%
info
Tool: queue manifest_parser · 70%
info
Tool: get_workflow manifest_parser · 70%
info
Tool: save_workflow manifest_parser · 70%
info
Tool: create_workflow manifest_parser · 70%
info
Tool: runpod manifest_parser · 70%
info
Tool: apps manifest_parser · 70%
info
Tool: comfyui-mcp-introspect manifest_parser · 75%
info
Tool: bisect manifest_parser · 70%
info
Tool: ping manifest_parser · 70%
info
Tool: echo manifest_parser · 70%
info
Tool: test-client manifest_parser · 75%
info
Tool: parked manifest_parser · 70%
info
Tool: retired-redirect-test-client manifest_parser · 75%
info
Tool: no-tools manifest_parser · 75%
info
Tool: call_tool manifest_parser · 70%
info
Tool: list_tools manifest_parser · 70%
info
Tool: test manifest_parser · 75%
info
Tool: c manifest_parser · 75%
info
Transport: stdio manifest_parser · 90%
info
Required env vars (270) manifest_parser · 80%
medium
Hardcoded OAuth client ID in artokun-comfyui-mcp-37a0b0c/src/services/oauth-flow.ts oauth_scope_analyzer · 80%
medium
Hardcoded OAuth client ID in artokun-comfyui-mcp-37a0b0c/src/services/code-provider-auth.ts oauth_scope_analyzer · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 90%
low
Permission: filesystem access detected permission_analyzer · 90%
high
Permission: shell access detected permission_analyzer · 95%
low
Permission: env_vars access detected permission_analyzer · 90%
info
SBOM generated: 371 components sbom_generator · 100%
critical
AWS Access Key ID found in artokun-comfyui-mcp-37a0b0c/src/comfyui/json-guard.ts secret_scanner · 95%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%