Agent skill

Recovering Poisoned Asset Cache

by Comfy-Org in Comfy-Org/ComfyUI_frontend

Diagnose and recover users stuck on a blank page or endless splash screen because a CDN or browser has pinned a 404 for a boot chunk.

GPL-3.0Auto-check passedDevOps & Cloud

Install Recovering Poisoned Asset Cache

skills CLI
$ npx skills add Comfy-Org/ComfyUI_frontend --skill recovering-poisoned-asset-cache -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Comfy-Org/ComfyUI_frontend recovering-poisoned-asset-cache --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Comfy-Org/ComfyUI_frontend.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/recovering-poisoned-asset-cache .claude/skills/recovering-poisoned-asset-cache && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
recovering-poisoned-asset-cache
GitHub stars
2.1k
Token cost
~1.9k tokens
SKILL.md length
832 words
Files
1
Skills in repo
22
Repo updated
First seen
Licence
GPL-3.0

At a glance

Diagnose and recover users stuck on a blank page or endless splash screen because a CDN or browser has pinned a 404 for a boot chunk.

  • Users report stuck on splash screen
  • SKILL.md covers Confirm the diagnosis before…, The three layers, and what…, Forcing every asset URL to… and Verify the recovery, plus 1 more section
  • Calls curl and pnpm; reaches cloud.comfy.org
  • Spinner forever

What it does

Recovering Poisoned Asset Cache is an agent skill from Comfy-Org/ComfyUI_frontend. Diagnose and recover users stuck on a blank page or endless splash screen because a CDN or browser has pinned a 404 for a boot chunk. Covers confirming the diagnosis, the origin-side fix, the edge purge, and forcing every asset URL to rotate when a redeploy cannot dislodge the cached 404. Use when users report "stuck on splash screen", "spinner forever", "blank page after deploy", a cached 404 on /assets/, or when reloading does not fix a broken app.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. The repository describes itself as: Official front-end implementation of ComfyUI. The licence is GPL-3.0.

When your agent uses it

  • Users report stuck on splash screen
  • Spinner forever
  • Blank page after deploy
  • A cached 404 on /assets/

Example prompts

  • “stuck on splash screen”
  • “spinner forever”
  • “blank page after deploy”
  • “/recovering-poisoned-asset-cache”

What it can do on your machine

Read from SKILL.md and the folder at commit d53a1c7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • cloud.comfy.org

    Also links to:

    • us5.datadoghq.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Recovering Poisoned Asset Cache loads about 1.9k tokens when it runs. Until then it costs about 122 tokens; SKILL.md has 832 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~122
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Comfy-Org/ComfyUI_frontend at commit d53a1c7, republished under its GPL-3.0 licence (© Comfy-Org). 832 words, ~1,853 tokens.

Download SKILL.mdSave it as .claude/skills/recovering-poisoned-asset-cache/SKILL.md (or your agent's skills folder).
name
recovering-poisoned-asset-cache
description
Diagnose and recover users stuck on a blank page or endless splash screen because a CDN or browser has pinned a 404 for a boot chunk. Covers confirming the diagnosis, the origin-side fix, the edge purge, and forcing every asset URL to rotate when a redeploy cannot dislodge the cached 404. Use when users report "stuck on splash screen", "spinner forever", "blank page after deploy", a cached 404 on /assets/*, or when reloading does not fix a broken app.

Recovering a Poisoned Asset Cache

A content-hashed chunk 404s. A cache stores that 404. Every client that reads from that cache is served a broken app, and reloading cannot fix it — the client is not asking origin, and with immutable it will not revalidate.

This happened as IR-105: nginx stamped Cache-Control: public, max-age=2592000, immutable on 404 responses, Cloudflare honoured it, and rolldown-runtime-*.js — the module runtime, without which no other chunk can load — was served as a cached 404 to a subset of users for as long as 30 days.

Confirm the diagnosis before acting

The same symptom ("stuck on splash / spinner forever") has at least three unrelated causes. Fixing the wrong one wastes an incident.

bash
# 1. Is a boot asset 404ing, and is the 404 itself cached?
curl -sI https://cloud.comfy.org/assets/<chunk>.js | grep -iE 'HTTP/|cache-control|cf-cache-status|age'
  • HTTP/2 404 + cf-cache-status: HIT → poisoned cache. This runbook applies.
  • HTTP/2 404 + cf-cache-status: MISS/BYPASS → origin is genuinely missing the file. Different problem: check the deploy and the bucket.
  • All boot assets 200 → not this. The app is booting and failing later. Check for an unregistered route or an auth stall instead; those present identically and this runbook will not help.
bash
# 2. Prove the no-store fix is live, using a path that cannot exist
curl -sI https://cloud.comfy.org/assets/does-not-exist-probe-QQQ.js | grep -iE 'HTTP/|cache-control|cf-cache-status'
# want: 404 + cache-control: no-store + cf-cache-status: BYPASS

Run the probe before concluding anything. A single healthy edge node is a sample of one — it does not prove other colos are clean.

The three layers, and what each fix reaches

Fixing one layer does not fix the others. Work down the list.

LayerFixReaches
Origin emits cacheable 404snginx no-store on 4xx/5xx for asset locations (Comfy-Org/cloud#6472)New poisonings only
Edge holds poisoned entriesCloudflare purge of the specific URLsNew users hitting that colo
Client has it pinnedNothing origin-side reaches themOnly a URL change does

That last row is the one people miss. A user whose browser holds max-age=2592000, immutable for a 404 is unreachable by any server-side action.

Forcing every asset URL to rotate

Why a redeploy is not enough

The instinct is "ship a new build, the hashes change". Measured, and it is false for exactly the chunks that matter. Two cloud builds of this repo differing only in commit hash:

  • 153 of 495 JS chunks rotated
  • rolldown-runtime, vendor-datadog, vendor-sentry, vendor-vue-core kept byte-identical filenames

A content hash tracks content. Vendor chunks are leaves whose content comes from node_modules, which a commit does not change. App chunks rotate because the import specifiers inside them changed — that cascade never reaches the leaves. So a redeploy leaves the poisoned vendor URLs exactly where they were.

The mechanism

In production, set the ASSET_CACHE_BUST repository variable on Comfy-Org/ComfyUI_frontend (Settings → Secrets and variables → Actions → Variables) to today's date, e.g. 20260818. Then deploy as normal.

A repo variable rather than a one-off build input is the whole point: the salt has to apply to every subsequent build, not just the recovery one. A manual one-shot build would fix the incident and then the next routine deploy would revert every filename to the poisoned names.

cloud-dispatch-build.yaml reads the variable into the frontend-asset-build dispatch payload as asset_cache_bust; frontend-asset-predeploy.yml in Comfy-Org/cloud passes it to both pnpm build invocations. Unset, the payload field is empty and the build is byte-identical to today's.

Locally, or for a manual verification build:

bash
ASSET_CACHE_BUST=20260818 pnpm build:cloud

ASSET_CACHE_BUST inserts its value into every emitted asset filename:

assets/rolldown-runtime-xtsTai4I.js  ->  assets/rolldown-runtime-cb20260818-xtsTai4I.js

Verified: 495 of 495 hashed JS/CSS assets get a new URL, index.html is rewritten to match, and unset behaviour is byte-identical to today's build. Non-hashed static files (favicon.ico, images/, CREDIT.txt, sorted-custom-node-map.json) do not carry hashes and are unaffected — if one of those is the poisoned file, this will not help it.

Use a date (20260818) rather than a counter. It is self-describing in a URL six months later and cannot collide.

Show full SKILL.md (243 more words)Show less
The trap

Only ever increment ASSET_CACHE_BUST. Never clear it, and never delete the repository variable.

Clearing it reverts every filename to exactly the names that were poisoned, and any client still holding those entries breaks again — with no new deploy to blame. Treat it as a permanent, monotonic deploy variable: once set, it stays set, and the next incident bumps it.

This is the failure mode to watch for during a repo-settings cleanup: the variable looks like leftover incident debris precisely when it is doing its job.

The salt changes the filename, not the content hash — xtsTai4I above is unchanged. That is deliberate and sufficient: caches key on URL.

Verify the recovery

bash
# New URLs are live and cacheable as 200s
curl -sI https://cloud.comfy.org/assets/rolldown-runtime-cb<salt>-<hash>.js | grep -iE 'HTTP/|cache-control'

# The old poisoned URL is gone from index.html
curl -s https://cloud.comfy.org/ | grep -oE 'assets/[^"]+\.js'

Then confirm in RUM that the failure actually stopped, rather than assuming:

@type:error @application.id:041a9897-5516-4b1f-a245-1a9aa6895488 @context.error_type:*

Dashboard: https://us5.datadoghq.com/dashboard/u9c-dtd-ui6

Note the ceiling on what RUM can tell you here: if a boot chunk 404s, no JavaScript executes, so no in-app reporter ever fires. A flat error chart is not evidence the cached-404 failure stopped — it is what that failure looks like. Confirm from the server side (404 rate on /assets/*) instead.

Coverage gaps worth knowing

  • The nginx no-store fix covers /assets/* but not /extensions/*. /extensions/core/clipspace.js still 404s as public, max-age=14400 and re-caches after every purge. Shorter TTL and not immutable, so it self-heals in ~4h — but it is uncovered.
  • Nobody on the cloud team could purge the CDN or add an edge rule during IR-105; both needed escalation. Budget for that delay, or fix the access.

© Comfy-Org, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/recovering-poisoned-asset-cache of Comfy-Org/ComfyUI_frontend.

Open the folder on GitHubat commit d53a1c7

Compare with similar skills

Recovering Poisoned Asset Cache next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Recovering Poisoned Asset Cache compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Recovering Poisoned Asset Cache this skillComfy-Org/ComfyUI_frontend2.1k—~1.9kAutomated safety check: PassGPL-3.0
Monitor CInrwl/nx29k6 repos~4.7kAutomated safety check: PassMIT
Terraform and OpenTofu Guideagentscope-ai/QwenPaw36k6 repos~4.2kAutomated safety check: PassApache-2.0
Vercel Optimize Auditvercel-labs/agent-skills32k8 repos~4.3kAutomated safety check: PassNone
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT

Similar skills

  • Monitor CI

    nrwl/nx

    Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.

    29k GitHub starsUsed in 6 repos~4.7k tokens
    DevOps & CloudAuto-check passed
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    36k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 8 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from Comfy-Org/ComfyUI_frontend

All 22 skills in this repo
  • Adding Deprecation Warnings

    Comfy-Org/ComfyUI_frontend

    Adds deprecation warnings for renamed or removed properties/APIs.

    2.1k GitHub stars~775 tokensUpdated today
    Auto-check passed
  • Agent Integration Replay

    Comfy-Org/ComfyUI_frontend

    Replay recorded agent conversations as Playwright tests against the real chat panel and canvas.

    2.1k GitHub stars~805 tokensUpdated today
    Auto-check: notes
  • Codegen Transform

    Comfy-Org/ComfyUI_frontend

    Transforms raw Playwright codegen output into ComfyUI convention-compliant tests.

    2.1k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Comment Sicko

    Comfy-Org/ComfyUI_frontend

    Dispatches the comment-sicko subagent to hunt gratuitous comments in a PR/diff, triages its raw findings, and posts a polite, professional writeup.

    2.1k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Hardening Flaky E2E Tests

    Comfy-Org/ComfyUI_frontend

    Diagnoses and fixes flaky Playwright e2e tests by replacing race-prone patterns with retry-safe alternatives.

    2.1k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Perf Fix With Proof

    Comfy-Org/ComfyUI_frontend

    Ships performance fixes with CI-proven improvement using stacked PRs.

    2.1k GitHub stars~1.6k tokensUpdated today
    Auto-check passed

Categories

Questions about Recovering Poisoned Asset Cache

What does Recovering Poisoned Asset Cache do?

Diagnose and recover users stuck on a blank page or endless splash screen because a CDN or browser has pinned a 404 for a boot chunk. Recovering Poisoned Asset Cache is an agent skill from Comfy-Org/ComfyUI_frontend. Diagnose and recover users stuck on a blank page or endless splash screen because a CDN or browser has pinned a 404 for a boot chunk.

When should I use Recovering Poisoned Asset Cache?

Recovering Poisoned Asset Cache fits situations like: users report stuck on splash screen; spinner forever; blank page after deploy; A cached 404 on /assets/.

How do I install Recovering Poisoned Asset Cache in Claude Code?

Run `npx skills add Comfy-Org/ComfyUI_frontend --skill recovering-poisoned-asset-cache -a claude-code`. Or copy the skill folder (.claude/skills/recovering-poisoned-asset-cache in Comfy-Org/ComfyUI_frontend) into .claude/skills/recovering-poisoned-asset-cache in your project. Claude Code loads it when a task matches its description.

How do I install Recovering Poisoned Asset Cache in Codex?

Run `npx skills add Comfy-Org/ComfyUI_frontend --skill recovering-poisoned-asset-cache -a codex`. Or copy the skill folder (.claude/skills/recovering-poisoned-asset-cache in Comfy-Org/ComfyUI_frontend) into .agents/skills/recovering-poisoned-asset-cache in your project. Codex loads it when a task matches its description.

Can I use Recovering Poisoned Asset Cache in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Comfy-Org/ComfyUI_frontend --skill recovering-poisoned-asset-cache -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/recovering-poisoned-asset-cache, .gemini/skills/recovering-poisoned-asset-cache, .github/skills/recovering-poisoned-asset-cache and .opencode/skills/recovering-poisoned-asset-cache in your project.

What does Recovering Poisoned Asset Cache need to run?

Going by SKILL.md and its folder, Recovering Poisoned Asset Cache needs the command-line tools its instructions call (curl and pnpm).

Does Recovering Poisoned Asset Cache access the network?

SKILL.md names 2 domains. In commands or code: cloud.comfy.org; the agent is likely to contact it when it follows the instructions. As links in the text: us5.datadoghq.com. This is read from the text; nothing was executed.

Is Recovering Poisoned Asset Cache safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Recovering Poisoned Asset Cache use?

Recovering Poisoned Asset Cache is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Recovering Poisoned Asset Cache use?

About 1.9k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Recovering Poisoned Asset Cache?

Skills that share tags, products or a category with Recovering Poisoned Asset Cache: Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 36k stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Analyze GitHub Action Logs (withastro/astro, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Recovering Poisoned Asset Cache?

Comfy-Org (a GitHub organization) maintains it in Comfy-Org/ComfyUI_frontend, which has 2,060 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 11, 2026.

Source: Comfy-Org/ComfyUI_frontend on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.