Back to Home
PurlieuStudios icon

comfyui-mcp

by PurlieuStudios

Overview

AI-powered image generation for Godot games, primarily for creating game assets like character portraits, item icons, and environment textures dynamically.

Installation

Run Command
python -m comfyui_mcp.server

Environment Variables

  • COMFYUI_URL

Security Notes

The `load_workflow` MCP tool allows an MCP client to specify an arbitrary `workflow_path` on the server's filesystem. The server then attempts to read this file and return its content as JSON. This constitutes a local file disclosure vulnerability, enabling a potentially malicious or compromised client to read sensitive files (e.g., configuration files, system files) from the server's machine if the server process has read access. There is no explicit path sanitization or restriction to a designated workflow directory for this feature in the provided code. Other aspects like API key handling and parameter substitution seem more robust.

Similar Servers

Stats

Interest Score0
Security Score3
Cost ClassLow
Avg Tokens200
Stars0
Forks0
Last Update2025-11-19

Tags

mcpcomfyuigodotai-generationimage-generationgame-developmentstable-diffusionworkflow-templatesasync