Agent skill

Layer Audit

by Comfy-Org in Comfy-Org/ComfyUI_frontend

Detect violations of the layered architecture import rules (base - platform - workbench - renderer).

GPL-3.0Auto-check passed

Install Layer Audit

skills CLI
$ npx skills add Comfy-Org/ComfyUI_frontend --skill layer-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Comfy-Org/ComfyUI_frontend layer-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Comfy-Org/ComfyUI_frontend.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/layer-audit .claude/skills/layer-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
layer-audit
GitHub stars
2.1k
Token cost
~808 tokens
SKILL.md length
269 words
Files
1
Skills in repo
22
Repo updated
First seen
Licence
GPL-3.0

At a glance

Detect violations of the layered architecture import rules (base - platform - workbench - renderer).

  • Works in 4 steps: Move the import target down -- if the… → Introduce an interface -- define an… → Move the importing file up -- if the… → …
  • SKILL.md covers Layer Hierarchy (bottom to top), How to Run, How to Read Results and When to Use, plus 2 more sections
  • Calls pnpm and jq

What it does

Layer Audit is an agent skill from Comfy-Org/ComfyUI_frontend. Detect violations of the layered architecture import rules (base - platform - workbench - renderer). Runs oxlint with the comfy/no-restricted-paths rule and generates a grouped report.

Its SKILL.md is about 810 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Official front-end implementation of ComfyUI. The licence is GPL-3.0.

Example prompts

  • “/layer-audit”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Move the import target down -- if the imported module doesn't depend on upper-layer concepts, move it to a lower layer
  2. Introduce an interface -- define an interface/type in the lower layer and implement it in the upper layer via dependency injection or a…
  3. Move the importing file up -- if the file logically belongs in a higher layer, relocate it
  4. Extract shared logic -- pull the shared functionality into base/ or a shared utility

What it can do on your machine

Read from SKILL.md and the folder at commit 850d562. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Layer Audit loads about 808 tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 269 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~808

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Comfy-Org/ComfyUI_frontend at commit 850d562, republished under its GPL-3.0 licence (© Comfy-Org). 269 words, ~808 tokens.

Download SKILL.mdSave it as .claude/skills/layer-audit/SKILL.md (or your agent's skills folder).
name
layer-audit
description
Detect violations of the layered architecture import rules (base -> platform -> workbench -> renderer). Runs oxlint with the comfy/no-restricted-paths rule and generates a grouped report.

Layer Architecture Audit

Finds imports that violate the layered architecture boundary rules enforced by comfy/no-restricted-paths (tools/oxlint-plugins/importPaths.ts) in .oxlintrc.json.

Layer Hierarchy (bottom to top)

renderer  (top -- can import from all lower layers)
   ^
workbench
   ^
platform
   ^
  base    (bottom -- cannot import from any upper layer)

Each layer may only import from layers below it.

How to Run

bash
# Run oxlint filtering for just the layer boundary rule violations
pnpm oxlint:main 2>&1 | grep 'comfy(no-restricted-paths)' | head -200

To get a full structured report, run:

bash
# Collect all violations from base/, platform/, workbench/ layers
pnpm exec oxlint src/base/ src/platform/ src/workbench/ --format=json 2>/dev/null \
  | jq -r '.diagnostics[] | select(.code == "comfy(no-restricted-paths)") | "\(.filename):\(.labels[0].span.line) \(.message)"' | sort

How to Read Results

Each violation line shows:

  • The file containing the bad import
  • The import path crossing the boundary
  • The message identifying which layer pair is violated
Grouping by Layer Pair

After collecting violations, group them by the layer pair pattern:

Layer pairMeaning
base -> platformbase/ importing from platform/
base -> workbenchbase/ importing from workbench/
base -> rendererbase/ importing from renderer/
platform -> workbenchplatform/ importing from workbench/
platform -> rendererplatform/ importing from renderer/
workbench -> rendererworkbench/ importing from renderer/

When to Use

  • Before creating a PR that adds imports between src/base/, src/platform/, src/workbench/, or src/renderer/
  • When auditing the codebase to find and plan migration of existing violations
  • After moving files between layers to verify no new violations were introduced

Fixing Violations

Common strategies to resolve a layer violation:

  1. Move the import target down -- if the imported module doesn't depend on upper-layer concepts, move it to a lower layer
  2. Introduce an interface -- define an interface/type in the lower layer and implement it in the upper layer via dependency injection or a registration pattern
  3. Move the importing file up -- if the file logically belongs in a higher layer, relocate it
  4. Extract shared logic -- pull the shared functionality into base/ or a shared utility

Reference

ResourcePath
ESLint config (rule definition)eslint.config.ts
Base layersrc/base/
Platform layersrc/platform/
Workbench layersrc/workbench/
Renderer layersrc/renderer/

© Comfy-Org, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/layer-audit of Comfy-Org/ComfyUI_frontend.

Open the folder on GitHubat commit 850d562

Compare with similar skills

Layer Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Layer Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Layer Audit this skillComfy-Org/ComfyUI_frontend2.1k—~808Automated safety check: PassGPL-3.0
Importasgeirtj/system_prompts_leaks69k—~3.5kAutomated safety check: PassCC0-1.0
Detecting Dnp3 Protocol Anomaliesmukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: PassApache-2.0
Threat Detectionalirezarezvani/claude-skills28k—~3.5kAutomated safety check: PassMIT
Configuring Host Based Intrusion Detectionmukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0
Detecting Arp Poisoning In Network Trafficmukul975/Anthropic-Cybersecurity-Skills34k—~3.8kAutomated safety check: NotesApache-2.0

Similar skills

  • Import

    asgeirtj/system_prompts_leaks

    Handle explicit /import requests for read-only transcript recovery and a resume checkpoint, or continue work from other coding agents and unnamed artifacts.

    69k GitHub stars~3.5k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Detecting Dnp3 Protocol Anomalies

    mukul975/Anthropic-Cybersecurity-Skills

    Detect anomalies in DNP3 communications used in SCADA/ICS systems by monitoring unauthorized control commands, firmware update attempts, protocol violations, and deviations from baseline traffic…

    34k GitHub stars~3.6k tokensUpdated 1 mo ago
    Data & AnalyticsAuto-check passed
  • Threat Detection

    alirezarezvani/claude-skills

    A skill your agent uses when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry.

    28k GitHub stars~3.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Configuring Host Based Intrusion Detection

    mukul975/Anthropic-Cybersecurity-Skills

    Configures host-based intrusion detection systems (HIDS) to monitor endpoint file integrity, system calls, and configuration changes for security violations.

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Arp Poisoning In Network Traffic

    mukul975/Anthropic-Cybersecurity-Skills

    Detect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP Inspection (DAI), Wireshark packet analysis, and custom Python monitoring scripts that flag gratuitous ARP floods, IP-to-MAC…

    34k GitHub stars~3.8k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Resemble Detect

    github/awesome-copilot

    Official

    Deepfake detection and media safety — detect AI-generated audio, images, video, and text, trace synthesis sources, apply watermarks, verify speaker identity, and analyze media intelligence using…

    40k GitHub starsUsed in 3 repos~4.1k tokens
    Media & CreativeAuto-check passed

More from Comfy-Org/ComfyUI_frontend

All 22 skills in this repo
  • Adding Deprecation Warnings

    Comfy-Org/ComfyUI_frontend

    Adds deprecation warnings for renamed or removed properties/APIs.

    2.1k GitHub stars~775 tokensUpdated today
    Auto-check passed
  • Agent Integration Replay

    Comfy-Org/ComfyUI_frontend

    Replay recorded agent conversations as Playwright tests against the real chat panel and canvas.

    2.1k GitHub stars~805 tokensUpdated today
    Auto-check: notes
  • Codegen Transform

    Comfy-Org/ComfyUI_frontend

    Transforms raw Playwright codegen output into ComfyUI convention-compliant tests.

    2.1k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Comment Sicko

    Comfy-Org/ComfyUI_frontend

    Dispatches the comment-sicko subagent to hunt gratuitous comments in a PR/diff, triages its raw findings, and posts a polite, professional writeup.

    2.1k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Hardening Flaky E2E Tests

    Comfy-Org/ComfyUI_frontend

    Diagnoses and fixes flaky Playwright e2e tests by replacing race-prone patterns with retry-safe alternatives.

    2.1k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Perf Fix With Proof

    Comfy-Org/ComfyUI_frontend

    Ships performance fixes with CI-proven improvement using stacked PRs.

    2.1k GitHub stars~1.6k tokensUpdated today
    Auto-check passed

Questions about Layer Audit

What does Layer Audit do?

Detect violations of the layered architecture import rules (base - platform - workbench - renderer). Layer Audit is an agent skill from Comfy-Org/ComfyUI_frontend. Detect violations of the layered architecture import rules (base - platform - workbench - renderer).

How do I install Layer Audit in Claude Code?

Run `npx skills add Comfy-Org/ComfyUI_frontend --skill layer-audit -a claude-code`. Or copy the skill folder (.claude/skills/layer-audit in Comfy-Org/ComfyUI_frontend) into .claude/skills/layer-audit in your project. Claude Code loads it when a task matches its description.

How do I install Layer Audit in Codex?

Run `npx skills add Comfy-Org/ComfyUI_frontend --skill layer-audit -a codex`. Or copy the skill folder (.claude/skills/layer-audit in Comfy-Org/ComfyUI_frontend) into .agents/skills/layer-audit in your project. Codex loads it when a task matches its description.

Can I use Layer Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Comfy-Org/ComfyUI_frontend --skill layer-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/layer-audit, .gemini/skills/layer-audit, .github/skills/layer-audit and .opencode/skills/layer-audit in your project.

What does Layer Audit need to run?

Going by SKILL.md and its folder, Layer Audit needs the command-line tools its instructions call (pnpm and jq).

Does Layer Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Layer Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Layer Audit use?

Layer Audit is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Layer Audit use?

About 808 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Layer Audit?

Skills that share tags, products or a category with Layer Audit: Import (asgeirtj/system_prompts_leaks, 69k stars), Detecting Dnp3 Protocol Anomalies (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Threat Detection (alirezarezvani/claude-skills, 28k stars) and Configuring Host Based Intrusion Detection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Layer Audit?

Comfy-Org (a GitHub organization) maintains it in Comfy-Org/ComfyUI_frontend, which has 2,054 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 7, 2026.

Source: Comfy-Org/ComfyUI_frontend on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.