badgids/comfyui-development-skills
v0.1.11MIT
Source-aware ComfyUI development skills that verify volatile behavior against the target install and current official upstream sources.
Changelog
00.01.11 - 2026-10-03
Cross-agent npx installation documentation release.
- Made
npx skills add badgids/comfyui-development-skills --skill '*'the recommended cross-agent full-pack installation path. - Added discovery, global-install, per-agent, local-checkout, single-skill, private-repository, and update examples.
- Documented that installing only
comfyui-developmentinstalls only the router and does not automatically install sibling specialists. - Clarified that
npx skills add owner/repoinstalls directly from the Git repository and does not require this project to publish its own npm CLI orbinexecutable. - Added
skills,skills.sh, andnpx-skillspackage keywords without adding an executable wrapper. - Added npx-specific troubleshooting and protocol notes, plus a release smoke-check for
npx skills add . --listwhen Node/network tooling is available. - Expanded regression coverage so the full-pack npx commands, update path, local discovery path, and non-executable package design stay documented.
- Bumped the canonical package version to
00.01.11/0.1.11.
00.01.10 - 2026-10-03
Attached-package audit and official-agent-guidance release.
- Audited the user-supplied
00.01.09package directly; its baseline suite passed 77/77 tests before changes. - Added
official-agent-guidance.mdso the pack discovers current Comfy-Org agent skills and repository-local instructions on demand instead of vendoring stale copies. - Clarified that current
comfy-cliagent skills ship withcomfy-cliundercomfy_cli/skills/, while the historical flatskills/area inComfy-Org/comfy-skillsis legacy/frozen. - Clarified that
comfy-claude-prompt-libraryis selective process guidance, not a universal dependency or ComfyUI implementation authority. - Routed relevant specialists to current/version-matched CLI or repository-local agent guidance without hardcoding its contents into this pack.
- Fixed a broken-symlink bypass in the guarded local self-modification path.
- Hardened checkout inspection so Git disables optional locks, terminal prompting, fsmonitor, and untracked-cache writes during read-only inspection.
- Added regression coverage for broken symlinks, read-only Git invocation, and the no-vendoring/current-agent-guidance policy.
- Fixed release-history tests to format canonical patch versions correctly beyond
00.01.09. - Bumped the canonical package version to
00.01.10/0.1.10.
00.01.09 - 2026-10-02
Second hardening and upstream-refresh release.
- Refreshed the public
Comfy-Orgupstream snapshot from 84 to 86 repositories and recorded the newly discoveredcomfy-cinematic-studioandcomfy-reshootrepositories without treating them as new authority routes. - Added bounded local JSON input handling for maintenance plans, findings, decisions, source registries, and workflow files.
- Bounded local self-modification backups against the combined old/new transaction size so generated backups remain restorable within the maintenance JSON safety limit.
- Added strict local-maintenance ledger validation so malformed state fails cleanly instead of surfacing later as missing-key or runtime errors.
- Made the maintenance CLI handle incomplete rollback
RuntimeErrorfailures as controlled command errors. - Strengthened workflow acceptance criteria to require a minimal load, queue, or execution check against the target when practical.
- Strengthened fallback frontend workflow validation by cross-checking node input/output link references against the central workflow link table.
- Corrected security and helper documentation for SCP-style Git remote username redaction and retained-history drift checks.
- Expanded regression coverage for input-size limits, malformed ledger state, incomplete rollback handling, refreshed upstream snapshot state, and workflow runtime acceptance.
- Rechecked the current Agent Skills, OpenAI Agent Plugins, Claude Code, Pi package, and ComfyUI workflow protocol expectations.
- Bumped the canonical package version to
00.01.09/0.1.9.
00.01.08 - 2026-09-28
Workflow naming and final hardening release.
- Renamed
comfyui-workflow-authoringtocomfyui-workflowsso workflow creation is obvious in skill discovery. - Updated router, installation, troubleshooting, architecture, and skill documentation for the new workflow skill name.
- Hardened guarded local self-modification so machine routing/snapshot files stay under the dedicated normal-maintenance path instead of being writable through the broader local skill-edit path.
- Strengthened local
SKILL.mdvalidation and maintenance rollback/drift checks. - Improved Git remote credential redaction and GitHub API URL validation.
- Expanded regression coverage for skill inventory, stale names, multi-transaction drift, rollback preflight, frontmatter validity, duplicate Python dictionary keys, and the new workflow skill.
- Fixed rollback-temp cleanup when a self-maintenance rollback replacement itself fails.
- Corrected testing documentation to reflect that skill-level license and author metadata are intentionally absent.
- Expanded CI coverage to Python 3.10, 3.11, 3.12, 3.13, and 3.14.
- Bumped the canonical package version to
00.01.08/0.1.8.
00.01.07 - 2026-09-28
Skill-context metadata cleanup release.
- Removed repeated
licensefrontmatter from everySKILL.md; licensing remains at the repository/package level. - Removed repeated
metadata.authorvalues from everySKILL.md; author and attribution remain in the README, package manifests, NOTICE, and license files. - Kept only operational skill metadata such as the skill version and the explicit-only self-maintenance invocation hint.
- Added regression checks that reject reintroduction of
licenseormetadata.authorin skill frontmatter. - Bumped the canonical package version to
00.01.07/0.1.7.
00.01.06 - 2026-09-28
README title-art release.
- Added the approved transparent ComfyUI Development Skills construction-worker title image to
docs/assets/logo.png. - Placed the title image directly below the author/copyright/license/version block and before the opening project description in
README.md. - Kept the existing architecture diagram in the documentation pages where it remains useful as technical documentation.
- Bumped the canonical package version to
00.01.06/0.1.6. - Added a regression check that keeps the approved title image below the attribution/license block and before the opening description.
00.01.05 - 2026-09-28
Transactional local-maintenance and audit-correction release.
- Replaced free-form post-validation self-editing with guarded
apply-local --yestransactions. Plans now use schema version 2 and contain the exact replacement text. - Added expected SHA-256 checks for modified files so a stale plan cannot overwrite a file that changed after review.
- Added same-filesystem atomic writes, before/after checksums, bounded transaction size, and automatic rollback when a file write or local-ledger update fails.
- Added guarded local backups and
restore-local --yesfor the latest transaction. Restore refuses to overwrite files that changed after the recorded local modification. - Added rollback of a restore operation if its ledger update fails, so cleanup cannot leave the file state and maintenance ledger disagreeing.
- Added local drift detection to
maintenance_boundary.py status. - Changed maintainer reports to label their generated Issues URL as a candidate destination. The helper does not contact GitHub and does not claim that the repository exists or has Issues enabled.
- Added
.gitignore,.npmignore, and CI protection so local maintenance backups cannot leak into an official repository or npm/Pi package. - Expanded public self-maintenance documentation with all four user choices, schema-v2 plans, transactional apply, drift checks, restore behavior, rollback rules, and the unverified Issue-destination rule.
- Documented the portable explicit-only limitation:
metadata.invocationis a package hint, while harness-specific fields such asdisable-model-invocationare not part of the portable Agent Skills frontmatter used here. - Fixed release-history/version documentation so
00.01.04is preserved and the next release after00.01.05is00.01.06. - Expanded regression coverage for stale plans, malformed JSON resources, skill-name mismatches, partial-write rollback, restore drift, failed restore-ledger updates, backup leakage, and continuous release history.
00.01.04 - 2026-09-28
Explicit maintainer-report and local self-modification release.
- Added four explicit boundary choices when upstream maintenance needs more than normal source routing: Report only, Self-modify only, Report and self-modify, or Stop.
- Added maintainer-ready GitHub Issue draft generation. The helper derives the configured maintainer repository from package metadata and never files an Issue automatically.
- Added a guarded local self-modification path for users who want their installed copy to learn durable new ComfyUI subsystems before an official package update exists.
- Limited local self-modification to non-executable skill knowledge under
skills/. It cannot rewrite the maintenance guard, executable helpers, public docs, tests, manifests, CI, versions, changelogs, licenses, release files, or publishing state. - Added validated local modification plans with path-traversal checks, create/modify target checks, extension restrictions, and explicit protection for the maintenance guard.
- Added
local-maintenance.jsonto record local divergence without changing the official package version. Reports identify such installs as the base version plus+local. - Added structured maintainer reason codes, affected-repository evidence, local workaround summaries, changed-file records, and validation evidence.
- Made Report and self-modify a first-class workflow: preserve the original finding, apply the local workaround, then regenerate the report with the local changes and remaining maintainer work.
- Kept official releases developer-controlled. Local self-modification cannot publish, commit, push, change official documentation, or build a release.
- Added regression coverage for maintainer reports, four-choice behavior, local-plan boundaries, guard protection, local-state recording, and report-plus-local-modification metadata.
00.01.03 - 2026-09-28
Explicit self-maintenance release.
- Added the explicit-only
comfyui-self-maintenanceskill. Ordinary ComfyUI work remains read-only toward the skill pack. - Added a full public
Comfy-Orgupstream snapshot baseline for change detection without treating the snapshot as authority. - Added guarded self-maintenance scan/apply tooling. Scan mode is read-only; apply mode requires
--yesand may change only the machine source-routing registry and upstream snapshot. - Added durable route learning for new official subsystems using existing specialist skills. Self-maintenance cannot create new skills.
- Added verified supersession routing so current-upstream work can follow replacement repositories while preserving older repositories for historical compatibility targets.
- Recorded the official
litegraph.jstoComfyUI_frontendauthority move in the machine routing registry. - Added heuristic README replacement signals that must be verified against official evidence before routing changes are applied.
- Added atomic two-file maintenance writes with rollback protection and cleanup.
- Kept release work developer-controlled: self-maintenance cannot change versions, changelogs, public docs, skills, tests, manifests, CI, release archives, or publishing state.
- Added human documentation and regression coverage for explicit invocation, snapshot integrity, route validation, replacement safety, rollback, and mutation boundaries.
00.01.02 - 2026-09-28
Protocol, validator, and safety audit release.
- Removed the redundant Claude
skillsmanifest entry because Claude Code already scans the standard rootskills/directory and extra manifest skill paths add to that scan. - Changed the root router to activate specialist skills by name instead of reading sibling
SKILL.mdfiles through../paths. - Fixed the workflow-validation specialist so it no longer references a helper path that exists only inside a sibling skill root.
- Updated the fallback workflow validator to accept current v1.0 object links as well as legacy v0.4 array links.
- Added duplicate node/link ID checks, malformed-link checks, destination input-slot checks, and better detection of partially malformed API-format graphs.
- Changed exact live node lookup so empty or unrelated node-specific responses do not count as success.
- Added bounded JSON response reads for ComfyUI and GitHub helper requests.
- Redacted credentials, query strings, and fragments from URL-style Git origins reported by the environment inspector.
- Added a clean error for malformed source registries whose JSON root is not an object.
- Corrected documentation that described every helper as read-only. Helpers are non-mutating toward ComfyUI/upstream services;
inspect_object_info.pycan write an explicitly requested local report. - Documented Python 3.10 as the helper floor and added Python 3.10 to CI.
- Expanded regression tests for protocol manifests, skill-root containment, modern workflow links, malformed/duplicate graph structures, response-size limits, credential redaction, node-not-found behavior, and registry root validation.
00.01.01 - 2026-09-28
Corrected documentation release.
- Rebuilt the public README and documentation navigation.
- Added practical guides for quick start, architecture, using the skills, custom-node development, workflow development, and frontend extension development.
- Added a diagram documentation page and expanded source-authority, protocol, testing, installation, development, and versioning docs.
- Replaced the broken source-routing SVG implementation with a conservative SVG subset that renders correctly across common renderers.
- Added two additional dark SVG diagrams for package architecture and source authority.
- Removed SVG filter usage after confirming that it caused the main node row to disappear in a real renderer.
- Expanded tests so Markdown image links are checked, not only normal links.
- Added documentation-index completeness checks.
- Added SVG safe-render checks that reject filters, masks, scripts, external resources, and embedded HTML.
- Added checks that every SVG asset is referenced by public documentation.
- Updated Codex manual skill paths to the current interoperable
.agents/skills/locations in public docs. - Added release instructions that rasterize and visually inspect every SVG before packaging.
- Fixed the versioning documentation examples and SemVer mapping.
00.01.00 - 2026-09-28
First public-ready release.
- Added a human-readable README and navigable documentation written in an ASD-STE100-inspired, ELI5 style.
- Added original dark SVG flowcharts using Lumen diagram workflow and dark-professional visual guidance.
- Added MIT licensing, attribution, contributing, security, and release documentation.
- Added Pi/npm, portable Agent Plugin, Codex compatibility, and Claude Code package manifests.
- Added installation instructions for Pi, Claude Code, Codex, Gemini CLI, OpenCode, generic Agent Skills harnesses, and the
npx skillsinstaller. - Added canonical project versioning. The canonical version is
00.01.00; semver manifests use0.1.0. - Added acceptance gates to every skill.
- Removed the duplicate top-level
SKILL.mdto avoid duplicate skill discovery. - Kept the complete
Comfy-Orgorganization as the upstream discovery namespace while retaining a curated routing index for common sources. - Added
pyisolate, the official React extension template, Comfy Cloud agent skills, Comfy Desktop, model tools, and quantization tooling to the curated source map where relevant. - Added safer ComfyUI HTTP handling. Remote API keys require explicit opt-in and HTTPS, authenticated requests do not follow redirects, and base URLs are validated before use.
- Added safer GitHub discovery. GitHub API requests are fixed to
api.github.com, redirects are blocked, registry data is validated, and pagination has a hard limit. - Changed
inspect_object_info.pyso it does not overwrite an existing output file unless--force-outputis supplied. Forced replacements use an atomic temp-file swap and clean up the temporary file if replacement fails. - Added Git command timeouts and clearer helper-script failure handling.
- Added an explicit npm/Pi package whitelist so Python bytecode caches and local environment files do not leak into published packages.
- Added GitHub Actions CI for tests, helper-script compilation, and npm/Pi package-content checks.
- Kept the Python test source in the npm/Pi package so
npm teststill works after packaging. - Expanded tests for manifests, version consistency, documentation links, install commands, source routing, SVG integrity, unsafe paths, HTTP safety, redirects, output-file handling, workflow validation, malformed registry data, pagination, and other error paths.
Future changes increment the canonical version by exactly 00.00.01.