ComfyUI Extension: ComfyUI-Image-Safety-Gate
Run ComfyUI workflows without the setup
No installs, no CUDA version roulette, no GPU sitting idle on your bill. Bring a workflow and run it in the browser.
Illustration-friendly NSFW + gore gate combining SmilingWolf WD tagger v3, CompVis CLIP safety checker, and OwenElliott image-safety-classifier-s NSFL signal with boolean OR. Drop-in compatible with the existing CLIP-based safety-checker node (matches the (IMAGE, nsfw) output signature).
README
ComfyUI-Image-Safety-Gate
ComfyUI custom node combining three safety signals with boolean OR. Tuned for workflows that generate illustration / anime-style content.
Available in ComfyUI-Manager — search for
ComfyUI-Image-Safety-Gatein the Custom Nodes Manager. See Install for details.
- SmilingWolf wd-tagger v3 family (ONNX)
— WaifuDiffusion tagger v3. Trained on Danbooru illustrations. Returns
rating probabilities
general / sensitive / questionable / explicit. We treatquestionable + explicitas the unsafe signal. Five variants are selectable from the node (see WD tagger variants). - CompVis/stable-diffusion-safety-checker
— CLIP-based concept similarity checker (same model the previous
ComfyUI-safety-checkerused). Sensitivity slider matches the old node. - OwenElliott/image-safety-classifier-s — SwiftFormer-based NSFL / NSFW / SFW classifier. We use only the NSFL dimension (gore / violence). The NSFW dimension over-triggers on illustrations, but the NSFL dimension empirically stays calm on illustrations and lights up on actual gore / violence.
Why this stack:
- WD tagger covers anime-style NSFW (sexual content) without illustration false positives.
- CLIP catches concept matches that WD might miss.
- image-safety-classifier-s NSFL covers gore / violence, which WD does not separate cleanly (Danbooru classifies blood / killing under "safe" rating).
OR keeps the policy conservative: block if any of the three flags the image.
Output
IMAGE: input image, unmodified (no censoring is applied here)nsfw(BOOLEAN):Trueif any of WD tagger, CLIP, or NSFL flags it as unsafe
For multi-image batches, nsfw is True if any image in the batch is flagged.
Inputs
| name | type | default | notes |
|-------------------|------------------|----------------|-----------------------------------------------------------------------|
| images | IMAGE | - | Standard ComfyUI image tensor |
| wd_variant | choice | eva02-large | Which WD tagger v3 variant to use (see table below) |
| sensitivity | FLOAT | 0.6 | CLIP safety checker sensitivity (matches the old node value) |
| nsfw_threshold | FLOAT | 0.35 | WD tagger threshold on rating_questionable + rating_explicit |
| nsfl_threshold | FLOAT | 0.5 | image-safety-classifier-s threshold on NSFL probability |
WD tagger variants
All variants are from SmilingWolf's v3 series. Larger models are slower / heavier but more accurate. All produce the same rating layout, so swapping variants does not require threshold retuning.
| wd_variant | repo | size | typical use |
|----------------|---------------------------------------------------------------------------------------|-------|----------------------------|
| vit | SmilingWolf/wd-vit-tagger-v3 | ~400MB | fastest, low VRAM |
| convnext | SmilingWolf/wd-convnext-tagger-v3 | ~400MB | alternative to vit |
| swinv2 | SmilingWolf/wd-swinv2-tagger-v3 | ~400MB | alternative to vit |
| vit-large | SmilingWolf/wd-vit-large-tagger-v3 | ~1.1GB | middle ground |
| eva02-large | SmilingWolf/wd-eva02-large-tagger-v3 | ~1.6GB | most accurate (default) |
The selected variant is downloaded on first use into
ComfyUI/models/safety_checker/wd-<variant>-tagger-v3/. Each variant is
cached separately, so switching does not re-download.
Sensitivity / threshold reference
CLIP sensitivity:
0.0: least sensitive0.5: explicit nudity threshold1.0: most sensitive (catches lingerie-like content)
WD tagger threshold (sum of questionable + explicit):
>= 0.50: high confidence NSFW0.30 - 0.50: borderline / sensitive content< 0.30: likely SFW
NSFL threshold (image-safety-classifier-s NSFL dimension):
>= 0.50: clear gore / dismemberment / corpse content (default)0.15 - 0.50: light blood / wound content (lower catches more)< 0.15: essentially no violence signal — most illustration content sits here regardless of depicted scene
Install
Option 1: ComfyUI-Manager (recommended)
Available in the ComfyUI-Manager registry since Comfy-Org/ComfyUI-Manager#3007.
- Open Manager → Custom Nodes Manager in ComfyUI.
- Search for
ComfyUI-Image-Safety-Gate. - Click Install, then restart ComfyUI.
Dependencies from requirements.txt are installed automatically.
Option 2: Manual (git clone)
cd ComfyUI/custom_nodes
git clone https://github.com/monkeykim111/ComfyUI-Image-Safety-Gate
pip install -r ComfyUI-Image-Safety-Gate/requirements.txt
Restart ComfyUI.
Model Files
On first use, the three models download into the standard safety_checker
folder:
ComfyUI/models/safety_checker/wd-<variant>-tagger-v3/
├── model.onnx
└── selected_tags.csv
ComfyUI/models/safety_checker/stable-diffusion-safety-checker/
├── config.json
├── preprocessor_config.json
└── pytorch_model.bin
ComfyUI/models/safety_checker/image-safety-classifier-s/
├── config.json
└── model.safetensors
If files already exist (e.g., previously downloaded for
ComfyUI-safety-checker or ComfyUI-image-safety-classifier), no network
access is made.
Notes
- All models are cached in memory per process. WD variants are cached per variant key, so toggling between variants in a session does not reload.
- WD tagger runs via
onnxruntime(CPU or GPU automatically depending on the installed provider). CLIP runs on CPU to match the original node's exact numerical behaviour. NSFL runs on GPU when CUDA is available. - Per-image log line shows each signal's decision and the final OR result, so disagreement cases are visible for later threshold tuning.
Run ComfyUI workflows without the setup
No installs, no CUDA version roulette, no GPU sitting idle on your bill. Bring a workflow and run it in the browser.