The safest ComfyUI workflow library is the one built into ComfyUI: Templates (Workflow, then Browse Workflow Templates) holds Comfy's official workflows for natively supported models, mostly built from core nodes, and prompts you to download the models. Beyond that, ComfyHub at comfy.org/workflows hosts official and community workflows, custom node packs add examples under Templates, Extensions, and ComfyUI's documentation tutorials link their workflows. Before loading a stranger's workflow, check which custom nodes it needs, because they run as ordinary Python on your machine.
Checked against ComfyUI's official documentation, security policy and ComfyHub on October 1, 2026. This update replaces the February 2026 version, which described a 50-workflow download pack with revenue and time-saving figures we could not support. There is no such pack; this guide points to the libraries that do exist.
Where to find ComfyUI workflows
| Source | What you get | Custom nodes | How far to trust it |
|---|---|---|---|
| Templates, inside ComfyUI | Official workflows for natively supported models; checks for missing model files and links the downloads | Mostly core nodes; a few, such as Wan2.2 Animate, name the packs they need | Maintained by Comfy |
| ComfyUI docs tutorials | A downloadable workflow for each tutorial, from text-to-image basics to Wan and SeedVR2 | Core, unless the page says otherwise | Maintained by Comfy |
| ComfyHub | Official and community workflows and apps; run them on Comfy Cloud or download them | Varies; Partner Node workflows need a Comfy account and credits | Check who published it |
| Node pack examples | Example workflows a pack ships in its example_workflows folder, shown under Templates, Extensions | Needs that pack | As far as you trust the pack |
| ComfyUI_examples | Older official examples as images with embedded workflows: SDXL, area composition, LCM and more | Core | Official, but many pages cover older models |
| Community posts and repos | Anything, from GitHub repos to forum and subreddit posts | Often several packs | Lowest: vet before loading |
Sources: Comfy's templates guide, whose rules for contributed templates exclude third-party nodes, the ComfyHub announcement from March 10, 2026, and the custom node templates guide. Comfy's community page lists the official Discord, forum and subreddit.
Using the built-in Templates browser
- Click the Templates icon in the sidebar, or open Workflow, then Browse Workflow Templates.
- Search by model or task, such as "Wan2.2" or "upscale", and click a template to load it.
- Download any models it flags as missing. Comfy Desktop downloads them for you; other installs download in the browser, and you move each file into the folder the template names under
ComfyUI/models. - Add your inputs and prompt, then click Run.
Templates ship as a separate Python package, comfyui-workflow-templates. If a template from a recent announcement is missing after you update ComfyUI, that package may be behind. The files themselves are public in the workflow_templates repository.
How to open a workflow file
- JSON files: drag the file onto the canvas or use File, then Open.
- Images and videos: built-in save nodes embed the workflow in PNG images and in animated WebP, MP4 and WebM files, so you can drag the output itself onto the canvas (workflow metadata).
- API-format JSON, exported for scripts, also loads, but without the layout.
Embedded workflows have limits that Comfy's docs spell out. A file re-encoded by another app may have lost them. The workflow does not include the models, input files or custom nodes it depends on. And the metadata is not a signature, so it proves nothing about who made the file; Comfy says to treat it as untrusted input.
When models are missing
Official templates carry download links for each model in the node's properties, with the file name, a direct URL and the ComfyUI/models subfolder. Comfy only embeds links from Hugging Face and Civitai, and only for safe formats such as .safetensors; it flags formats it treats as unsafe and hides their links. Two gotchas from the templates guide:
- The missing-model check only looks in the top-level folder. A file you keep in a subfolder, such as
diffusion_models/wan_video, triggers the prompt anyway; ignore it and select the file in the loader node. - A workflow from the community may expect a file name you do not have. Pick the closest match in the loader, and check that it belongs to the same model family.
Prefer .safetensors files wherever you download models. Hugging Face describes the format as a way to store tensors safely, as opposed to pickle.
When custom nodes are missing
A workflow that uses nodes you do not have opens with those nodes marked as missing. With ComfyUI-Manager enabled, a prompt offers Install All, or Open Manager to review the packs first (Manager docs). Review first. Then:
- Update ComfyUI before installing anything. Nodes from a recent template may be core nodes your version lacks.
- Install from the Comfy Registry. Manager's new interface only installs Registry packs and no longer installs from a Git URL, which Comfy says is for security and stability.
- Treat manual installs as the risky path. Packs outside the Registry need a
git cloneintoComfyUI/custom_nodesplus their Python dependencies, and Comfy's install guide warns to use only trusted, widely used nodes. - Restart and read the log. Look for
import failedlines after installing.
Safety checklist for shared workflows
ComfyUI's security policy is blunt: custom nodes are arbitrary Python code, trusted as much as any other software you install, and the server binds to 127.0.0.1 so only your own machine can reach it. A workflow built only from core nodes that could still run code or leak files is what Comfy counts as a vulnerability. Everything beyond that baseline is your call.
- List the node packs before you install. Look each one up on the Comfy Registry. Comfy says Registry nodes are scanned for malicious behavior such as custom pip wheels and arbitrary system calls, and its standards ban
evalandexec, runtime pip installs and obfuscated code. - Be wary of nodes that run code you type in. In April 2026, Censys researchers reported more than 1,000 ComfyUI servers reachable without authentication and a cryptomining botnet targeting them through custom nodes that run raw Python from their inputs, falling back on ComfyUI-Manager where those nodes were absent (The Hacker News).
- Remember dependencies can be compromised too. In December 2024, a cryptominer shipped in versions 8.3.41 and 8.3.42 of the ultralytics Python package, a dependency of popular node packs such as ComfyUI-Impact-Pack; it affected Mac and Linux, and Manager was updated to pin a safe version (Comfy's statement).
- Do not expose ComfyUI to the internet. Starting it with
--listenopens it to your network, and Comfy's policy makes securing that your job, with a firewall, reverse proxy or authentication. - Keep Manager's security level on. Its security levels (strong, normal, normal- and weak) block risky actions such as installing from a Git URL; Comfy Desktop offers Strict, Standard, Relaxed and Permissive levels and recommends Standard (Manager install).
- Take a restore point first. Comfy Desktop snapshots record your ComfyUI version, custom nodes and Python packages, and Manager has snapshots too.
- If ComfyUI breaks after an install, start it with
--disable-all-custom-nodes, confirm the problem disappears, then re-enable packs in halves to find the culprit (troubleshooting guide).
Good first workflows by goal
All of these are official templates; search the name in the Templates browser. Licenses are for the main model and come from each model card. Wan2.2 Animate also needs two custom node packs, which its guide lists.
| Goal | Template to search | Main model license |
|---|---|---|
| Fast text to image | Z-Image-Turbo: Text to Image | Apache 2.0 |
| Text to image with readable text | Qwen-Image | Apache 2.0 |
| Edit with a reference image | Qwen-Image-Edit-2511, or Flux.2 [Klein] 4B: Image Edit | Apache 2.0 |
| Upscale an image or video | SeedVR2 3B Int8: Upscale Image | Apache 2.0 |
| Remove a background | BiRefNet: Remove Background | MIT |
| Turn an image into video | Wan2.2 14B I2V, or Wan2.2 5B | Apache 2.0 |
| Animate a character from a video | Wan2.2 Animate, or Wan Animate 2 | Apache 2.0 |
Want to go further? Our advanced ComfyUI workflows guide walks through five complete builds, our techniques explainer covers ControlNet, regional prompts and upscaling, and the Wan 2.2 Animate tutorial covers character animation. Partner Node templates on ComfyHub, such as Wan 3.0 or Kling, call paid APIs and need a Comfy account with prepaid credits (Partner Nodes); Comfy says ComfyUI itself stays free for local users.
Sharing your own workflows
- Save the JSON with Ctrl+S, or export an API-format copy for scripts.
- Check what your images carry. Outputs embed the full workflow, prompts included, unless you start ComfyUI with
--disable-metadata. - Comfy Cloud share links include the workflow's inputs, outputs and assets, such as uploaded images and masks, so never share private media that way (share workflows).
- Node developers can ship examples in an
example_workflowsfolder, which appear in the Templates browser, and reusable groups in asubgraphsfolder, which appear as subgraph blueprints. You can propose an official template by pull request to the templates repository, but it must not use third-party nodes or duplicate an existing template.
ComfyUI Workflow Library FAQ
Where can I find ComfyUI workflows?
Start with the Templates browser inside ComfyUI (Workflow, then Browse Workflow Templates), which holds Comfy's official workflows for natively supported models. After that, try the workflow linked from each ComfyUI documentation tutorial, ComfyHub at comfy.org/workflows, and the example workflows that custom node packs add under Templates, Extensions.
Are ComfyUI workflows safe to download?
A workflow file is data, but the custom nodes it asks you to install are ordinary Python that runs with your permissions. Workflows that use only built-in nodes are the safe baseline in ComfyUI's security policy. For anything else, check which node packs it needs, install them from the Comfy Registry through ComfyUI-Manager, and keep ComfyUI on its default 127.0.0.1 address.
How do I load a ComfyUI workflow from an image?
Drag the PNG onto the ComfyUI canvas or open it with File, then Open. Built-in save nodes embed the workflow in PNG images and in animated WebP, MP4 and WebM files. If an app has re-encoded the file, the metadata may be gone.
Why does a ComfyUI workflow show missing nodes?
It uses custom nodes you have not installed, or core nodes newer than your ComfyUI. Update ComfyUI first, then use ComfyUI-Manager's missing-nodes prompt to install from the Comfy Registry. Nodes that are not in the Registry need a manual install, so vet those carefully.
What are the best ComfyUI workflows for beginners?
The official templates, because they are maintained by Comfy, mostly use core nodes and link the models they need. Good starting points are the Z-Image-Turbo text-to-image template for fast images, Qwen-Image-Edit-2511 for reference edits, SeedVR2 for upscaling and Wan 2.2 5B for image to video.
How do I share a ComfyUI workflow?
Save it as JSON, or share an output image, since built-in save nodes embed the workflow unless ComfyUI runs with --disable-metadata. On Comfy Cloud you can create a share link, but it includes the workflow's inputs, outputs and assets, so do not share private media that way.
Related Reads
Want the full AI Influencers playbook?
The complete pipeline for building virtual brands at scale — identity engineering, ComfyUI production, IP governance, and the distribution flywheel.