Benign comfyui Download

radiance 3.5.2

Explicit unsafe YAML deserializationFile under a vendored source dependency path

Evidence

imports os lines 1–16
1import nuke
2import nukescripts
3import socket
4import struct
5import threading
6import json
7import ast
8import os
9import urllib.request
10import urllib.error
11import random
12
13PORT = int(os.environ.get("RADIANCE_NUKE_PORT", "1986"))
14# v1.1: Configurable via env vars for studio/farm deployments.
15# Bind host: 127.0.0.1 by default (loopback only — safe).
16# Set RADI …
Authentication token name literal lines 16–34
16:62… a separate machine.
17BIND_HOST = os.environ.get("RADIANCE_NUKE_BIND_HOST", os.environ.get("RADIANCE_NUKE_HOST", "127.0.0.1"))
18# ComfyUI base URL for history/prompt API calls.
19COMFY_URL = os.environ.get("RADIANCE_COMFY_URL", "http://127.0.0.1:8188")
20def load_or_create_token():
21 """The token shared with ComfyUI: RADIANCE_DCC_AUTH_TOKEN, else
22 ~/.radiance/dcc_token, created on first use. A copy of
23 radiance.core.dcc_auth.load_or_create_token (this script runs inside Nuke,
24 where the package is not importable); keep the two identical."""
25 import secrets
26 tok = (os.environ.get("RADIANCE_DCC_AUTH_TOKEN") or "").strip()
27 if tok:
28 return tok
29 path = os.path.join(os.path.expanduser("~"), ".radiance", "dcc_token")
30 try:
31 with open(path, "r", encoding="utf-8") as fh:
32 tok = fh.read().strip()
33 if tok:
34 …
Python opens a file descriptor for writing lines 37–45
37:2… tok = secrets.token_hex(32)
38 try:
39 os.makedirs(os.path.dirname(path), exist_ok=True)
40 fd = os.open(path, os.O_WRONLY | os.O_CREAT | os.O_EXCL, 0o600)
41 with os.fdopen(fd, "w", encoding="utf-8") as fh:
42 fh.write(tok)
43 except FileExistsError:
44 with open(path, "r", encoding="utf-8") as fh:
45 …
Auth-like constant assignment lines 52–62
52:54… istener refused every
53# command until both Nuke and ComfyUI were given the same variable.
54DCC_AUTH_TOKEN = load_or_create_token()
55RUNNING = True
56_SERVER_THREAD = None
⋯6 lines
__import__ function lines 74–93
74:180… ════════════════════
75
76# Dangerous patterns that must never appear in incoming commands
77_BLOCKED_PATTERNS = [
78 "import os",
79 "import sys",
80 "import subprocess",
81 "import shutil",
82 "import socket",
83 "import http",
84 "import urllib",
85 "__import__",
86 "__builtins__",
87 "__class__",
⋯6 lines

Showing the top 5 files — 6 more files (107 regions) not shown.

No evidence locations were recorded for this file. Raw result

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.