Skip to content

badgids/comfyui-development-skills

v0.1.11MIT

Source-aware ComfyUI development skills that verify volatile behavior against the target install and current official upstream sources.

Changelog

00.01.11 - 2026-10-03

Cross-agent npx installation documentation release.

  • Made npx skills add badgids/comfyui-development-skills --skill '*' the recommended cross-agent full-pack installation path.
  • Added discovery, global-install, per-agent, local-checkout, single-skill, private-repository, and update examples.
  • Documented that installing only comfyui-development installs only the router and does not automatically install sibling specialists.
  • Clarified that npx skills add owner/repo installs directly from the Git repository and does not require this project to publish its own npm CLI or bin executable.
  • Added skills, skills.sh, and npx-skills package keywords without adding an executable wrapper.
  • Added npx-specific troubleshooting and protocol notes, plus a release smoke-check for npx skills add . --list when Node/network tooling is available.
  • Expanded regression coverage so the full-pack npx commands, update path, local discovery path, and non-executable package design stay documented.
  • Bumped the canonical package version to 00.01.11 / 0.1.11.

00.01.10 - 2026-10-03

Attached-package audit and official-agent-guidance release.

  • Audited the user-supplied 00.01.09 package directly; its baseline suite passed 77/77 tests before changes.
  • Added official-agent-guidance.md so the pack discovers current Comfy-Org agent skills and repository-local instructions on demand instead of vendoring stale copies.
  • Clarified that current comfy-cli agent skills ship with comfy-cli under comfy_cli/skills/, while the historical flat skills/ area in Comfy-Org/comfy-skills is legacy/frozen.
  • Clarified that comfy-claude-prompt-library is selective process guidance, not a universal dependency or ComfyUI implementation authority.
  • Routed relevant specialists to current/version-matched CLI or repository-local agent guidance without hardcoding its contents into this pack.
  • Fixed a broken-symlink bypass in the guarded local self-modification path.
  • Hardened checkout inspection so Git disables optional locks, terminal prompting, fsmonitor, and untracked-cache writes during read-only inspection.
  • Added regression coverage for broken symlinks, read-only Git invocation, and the no-vendoring/current-agent-guidance policy.
  • Fixed release-history tests to format canonical patch versions correctly beyond 00.01.09.
  • Bumped the canonical package version to 00.01.10 / 0.1.10.

00.01.09 - 2026-10-02

Second hardening and upstream-refresh release.

  • Refreshed the public Comfy-Org upstream snapshot from 84 to 86 repositories and recorded the newly discovered comfy-cinematic-studio and comfy-reshoot repositories without treating them as new authority routes.
  • Added bounded local JSON input handling for maintenance plans, findings, decisions, source registries, and workflow files.
  • Bounded local self-modification backups against the combined old/new transaction size so generated backups remain restorable within the maintenance JSON safety limit.
  • Added strict local-maintenance ledger validation so malformed state fails cleanly instead of surfacing later as missing-key or runtime errors.
  • Made the maintenance CLI handle incomplete rollback RuntimeError failures as controlled command errors.
  • Strengthened workflow acceptance criteria to require a minimal load, queue, or execution check against the target when practical.
  • Strengthened fallback frontend workflow validation by cross-checking node input/output link references against the central workflow link table.
  • Corrected security and helper documentation for SCP-style Git remote username redaction and retained-history drift checks.
  • Expanded regression coverage for input-size limits, malformed ledger state, incomplete rollback handling, refreshed upstream snapshot state, and workflow runtime acceptance.
  • Rechecked the current Agent Skills, OpenAI Agent Plugins, Claude Code, Pi package, and ComfyUI workflow protocol expectations.
  • Bumped the canonical package version to 00.01.09 / 0.1.9.

00.01.08 - 2026-09-28

Workflow naming and final hardening release.

  • Renamed comfyui-workflow-authoring to comfyui-workflows so workflow creation is obvious in skill discovery.
  • Updated router, installation, troubleshooting, architecture, and skill documentation for the new workflow skill name.
  • Hardened guarded local self-modification so machine routing/snapshot files stay under the dedicated normal-maintenance path instead of being writable through the broader local skill-edit path.
  • Strengthened local SKILL.md validation and maintenance rollback/drift checks.
  • Improved Git remote credential redaction and GitHub API URL validation.
  • Expanded regression coverage for skill inventory, stale names, multi-transaction drift, rollback preflight, frontmatter validity, duplicate Python dictionary keys, and the new workflow skill.
  • Fixed rollback-temp cleanup when a self-maintenance rollback replacement itself fails.
  • Corrected testing documentation to reflect that skill-level license and author metadata are intentionally absent.
  • Expanded CI coverage to Python 3.10, 3.11, 3.12, 3.13, and 3.14.
  • Bumped the canonical package version to 00.01.08 / 0.1.8.

00.01.07 - 2026-09-28

Skill-context metadata cleanup release.

  • Removed repeated license frontmatter from every SKILL.md; licensing remains at the repository/package level.
  • Removed repeated metadata.author values from every SKILL.md; author and attribution remain in the README, package manifests, NOTICE, and license files.
  • Kept only operational skill metadata such as the skill version and the explicit-only self-maintenance invocation hint.
  • Added regression checks that reject reintroduction of license or metadata.author in skill frontmatter.
  • Bumped the canonical package version to 00.01.07 / 0.1.7.

00.01.06 - 2026-09-28

README title-art release.

  • Added the approved transparent ComfyUI Development Skills construction-worker title image to docs/assets/logo.png.
  • Placed the title image directly below the author/copyright/license/version block and before the opening project description in README.md.
  • Kept the existing architecture diagram in the documentation pages where it remains useful as technical documentation.
  • Bumped the canonical package version to 00.01.06 / 0.1.6.
  • Added a regression check that keeps the approved title image below the attribution/license block and before the opening description.

00.01.05 - 2026-09-28

Transactional local-maintenance and audit-correction release.

  • Replaced free-form post-validation self-editing with guarded apply-local --yes transactions. Plans now use schema version 2 and contain the exact replacement text.
  • Added expected SHA-256 checks for modified files so a stale plan cannot overwrite a file that changed after review.
  • Added same-filesystem atomic writes, before/after checksums, bounded transaction size, and automatic rollback when a file write or local-ledger update fails.
  • Added guarded local backups and restore-local --yes for the latest transaction. Restore refuses to overwrite files that changed after the recorded local modification.
  • Added rollback of a restore operation if its ledger update fails, so cleanup cannot leave the file state and maintenance ledger disagreeing.
  • Added local drift detection to maintenance_boundary.py status.
  • Changed maintainer reports to label their generated Issues URL as a candidate destination. The helper does not contact GitHub and does not claim that the repository exists or has Issues enabled.
  • Added .gitignore, .npmignore, and CI protection so local maintenance backups cannot leak into an official repository or npm/Pi package.
  • Expanded public self-maintenance documentation with all four user choices, schema-v2 plans, transactional apply, drift checks, restore behavior, rollback rules, and the unverified Issue-destination rule.
  • Documented the portable explicit-only limitation: metadata.invocation is a package hint, while harness-specific fields such as disable-model-invocation are not part of the portable Agent Skills frontmatter used here.
  • Fixed release-history/version documentation so 00.01.04 is preserved and the next release after 00.01.05 is 00.01.06.
  • Expanded regression coverage for stale plans, malformed JSON resources, skill-name mismatches, partial-write rollback, restore drift, failed restore-ledger updates, backup leakage, and continuous release history.

00.01.04 - 2026-09-28

Explicit maintainer-report and local self-modification release.

  • Added four explicit boundary choices when upstream maintenance needs more than normal source routing: Report only, Self-modify only, Report and self-modify, or Stop.
  • Added maintainer-ready GitHub Issue draft generation. The helper derives the configured maintainer repository from package metadata and never files an Issue automatically.
  • Added a guarded local self-modification path for users who want their installed copy to learn durable new ComfyUI subsystems before an official package update exists.
  • Limited local self-modification to non-executable skill knowledge under skills/. It cannot rewrite the maintenance guard, executable helpers, public docs, tests, manifests, CI, versions, changelogs, licenses, release files, or publishing state.
  • Added validated local modification plans with path-traversal checks, create/modify target checks, extension restrictions, and explicit protection for the maintenance guard.
  • Added local-maintenance.json to record local divergence without changing the official package version. Reports identify such installs as the base version plus +local.
  • Added structured maintainer reason codes, affected-repository evidence, local workaround summaries, changed-file records, and validation evidence.
  • Made Report and self-modify a first-class workflow: preserve the original finding, apply the local workaround, then regenerate the report with the local changes and remaining maintainer work.
  • Kept official releases developer-controlled. Local self-modification cannot publish, commit, push, change official documentation, or build a release.
  • Added regression coverage for maintainer reports, four-choice behavior, local-plan boundaries, guard protection, local-state recording, and report-plus-local-modification metadata.

00.01.03 - 2026-09-28

Explicit self-maintenance release.

  • Added the explicit-only comfyui-self-maintenance skill. Ordinary ComfyUI work remains read-only toward the skill pack.
  • Added a full public Comfy-Org upstream snapshot baseline for change detection without treating the snapshot as authority.
  • Added guarded self-maintenance scan/apply tooling. Scan mode is read-only; apply mode requires --yes and may change only the machine source-routing registry and upstream snapshot.
  • Added durable route learning for new official subsystems using existing specialist skills. Self-maintenance cannot create new skills.
  • Added verified supersession routing so current-upstream work can follow replacement repositories while preserving older repositories for historical compatibility targets.
  • Recorded the official litegraph.js to ComfyUI_frontend authority move in the machine routing registry.
  • Added heuristic README replacement signals that must be verified against official evidence before routing changes are applied.
  • Added atomic two-file maintenance writes with rollback protection and cleanup.
  • Kept release work developer-controlled: self-maintenance cannot change versions, changelogs, public docs, skills, tests, manifests, CI, release archives, or publishing state.
  • Added human documentation and regression coverage for explicit invocation, snapshot integrity, route validation, replacement safety, rollback, and mutation boundaries.

00.01.02 - 2026-09-28

Protocol, validator, and safety audit release.

  • Removed the redundant Claude skills manifest entry because Claude Code already scans the standard root skills/ directory and extra manifest skill paths add to that scan.
  • Changed the root router to activate specialist skills by name instead of reading sibling SKILL.md files through ../ paths.
  • Fixed the workflow-validation specialist so it no longer references a helper path that exists only inside a sibling skill root.
  • Updated the fallback workflow validator to accept current v1.0 object links as well as legacy v0.4 array links.
  • Added duplicate node/link ID checks, malformed-link checks, destination input-slot checks, and better detection of partially malformed API-format graphs.
  • Changed exact live node lookup so empty or unrelated node-specific responses do not count as success.
  • Added bounded JSON response reads for ComfyUI and GitHub helper requests.
  • Redacted credentials, query strings, and fragments from URL-style Git origins reported by the environment inspector.
  • Added a clean error for malformed source registries whose JSON root is not an object.
  • Corrected documentation that described every helper as read-only. Helpers are non-mutating toward ComfyUI/upstream services; inspect_object_info.py can write an explicitly requested local report.
  • Documented Python 3.10 as the helper floor and added Python 3.10 to CI.
  • Expanded regression tests for protocol manifests, skill-root containment, modern workflow links, malformed/duplicate graph structures, response-size limits, credential redaction, node-not-found behavior, and registry root validation.

00.01.01 - 2026-09-28

Corrected documentation release.

  • Rebuilt the public README and documentation navigation.
  • Added practical guides for quick start, architecture, using the skills, custom-node development, workflow development, and frontend extension development.
  • Added a diagram documentation page and expanded source-authority, protocol, testing, installation, development, and versioning docs.
  • Replaced the broken source-routing SVG implementation with a conservative SVG subset that renders correctly across common renderers.
  • Added two additional dark SVG diagrams for package architecture and source authority.
  • Removed SVG filter usage after confirming that it caused the main node row to disappear in a real renderer.
  • Expanded tests so Markdown image links are checked, not only normal links.
  • Added documentation-index completeness checks.
  • Added SVG safe-render checks that reject filters, masks, scripts, external resources, and embedded HTML.
  • Added checks that every SVG asset is referenced by public documentation.
  • Updated Codex manual skill paths to the current interoperable .agents/skills/ locations in public docs.
  • Added release instructions that rasterize and visually inspect every SVG before packaging.
  • Fixed the versioning documentation examples and SemVer mapping.

00.01.00 - 2026-09-28

First public-ready release.

  • Added a human-readable README and navigable documentation written in an ASD-STE100-inspired, ELI5 style.
  • Added original dark SVG flowcharts using Lumen diagram workflow and dark-professional visual guidance.
  • Added MIT licensing, attribution, contributing, security, and release documentation.
  • Added Pi/npm, portable Agent Plugin, Codex compatibility, and Claude Code package manifests.
  • Added installation instructions for Pi, Claude Code, Codex, Gemini CLI, OpenCode, generic Agent Skills harnesses, and the npx skills installer.
  • Added canonical project versioning. The canonical version is 00.01.00; semver manifests use 0.1.0.
  • Added acceptance gates to every skill.
  • Removed the duplicate top-level SKILL.md to avoid duplicate skill discovery.
  • Kept the complete Comfy-Org organization as the upstream discovery namespace while retaining a curated routing index for common sources.
  • Added pyisolate, the official React extension template, Comfy Cloud agent skills, Comfy Desktop, model tools, and quantization tooling to the curated source map where relevant.
  • Added safer ComfyUI HTTP handling. Remote API keys require explicit opt-in and HTTPS, authenticated requests do not follow redirects, and base URLs are validated before use.
  • Added safer GitHub discovery. GitHub API requests are fixed to api.github.com, redirects are blocked, registry data is validated, and pagination has a hard limit.
  • Changed inspect_object_info.py so it does not overwrite an existing output file unless --force-output is supplied. Forced replacements use an atomic temp-file swap and clean up the temporary file if replacement fails.
  • Added Git command timeouts and clearer helper-script failure handling.
  • Added an explicit npm/Pi package whitelist so Python bytecode caches and local environment files do not leak into published packages.
  • Added GitHub Actions CI for tests, helper-script compilation, and npm/Pi package-content checks.
  • Kept the Python test source in the npm/Pi package so npm test still works after packaging.
  • Expanded tests for manifests, version consistency, documentation links, install commands, source routing, SVG integrity, unsafe paths, HTTP safety, redirects, output-file handling, workflow validation, malformed registry data, pagination, and other error paths.

Future changes increment the canonical version by exactly 00.00.01.