Stability Matrix is a package manager for AI image tools. Instead of cloning repositories and fighting Python versions, you pick ComfyUI, Stable Diffusion WebUI Forge or reForge, Automatic1111, SD.Next, Fooocus, InvokeAI, SwarmUI, or trainers such as Kohya's GUI, OneTrainer and FluxGym, and it installs each one with its own embedded Python and Git, then updates and launches them from one window. Extensions for ComfyUI, Automatic1111 and SD.Next can be managed from the same place.
The part that saves the most disk space is the shared model library: checkpoints, LoRAs and other models live in one folder that every installed interface reads, so you never keep three copies of the same 6 GB file. A built-in browser imports models from CivitAI and Hugging Face with their metadata and preview images, and pauses and resumes downloads. It also has its own generation interface, Inference, built on ComfyUI, with tabbed projects and prompt autocompletion.
Stability Matrix is made by Lykos AI and has about 8,900 stars. The source code is AGPL-3.0, while the prebuilt binaries are distributed under Lykos AI's own end-user licence agreement. The latest release, 2.16.4, came out in September 2026.
- Repository: github.com/LykosAI/StabilityMatrix
- Licence: AGPL-3.0 (GNU Affero General Public License v3.0)
- Language: C#. Stars: 8,865. Forks: 606. Last push: Oct 1, 2026.
- Scan: safe, Oct 1, 2026, commit 604387e
Who it is for
People who want to try several Stable Diffusion and Flux interfaces without learning Python environment management, and anyone whose model folder has grown large enough to hurt.
Getting started
1. Windows: download the latest build, unzip it and run StabilityMatrix.exe
start https://github.com/LykosAI/StabilityMatrix/releases/latest/download/StabilityMatrix-win-x64.zip2. macOS (Apple Silicon): download the disk image
open https://github.com/LykosAI/StabilityMatrix/releases/latest/download/StabilityMatrix-macos-arm64.dmg3. Linux: the AppImage zip, or the stabilitymatrix package on the AUR
curl -LO https://github.com/LykosAI/StabilityMatrix/releases/latest/download/StabilityMatrix-linux-x64.zip4. Pick a data folder, then add a package such as ComfyUI or Forge from the Packages tab
# Packages > Add Package > ComfyUI > InstallStability Matrix is portable: its data folder holds every package and model, and can be moved to another drive or computer. It sends crash reports and performance traces to Sentry unless you launch it with --no-sentry. The interfaces it installs set their own hardware needs, usually a reasonably recent GPU; NVIDIA cards are the best supported.
Safety scan
We cloned LykosAI/StabilityMatrix at commit 604387e on Oct 1, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets, no pattern hits, no bare-IP URLs and no install hooks across 1,843 files and about 205,000 lines, 193,000 of them C#.
- 34 committed binaries: an embeddable Python 3.10 for Windows (python.exe, the core DLLs including OpenSSL 1.1, which is past end of life, and extension modules) in the original WPF project's StabilityMatrix/Assets folder, and 7-Zip executables for Windows, macOS and Linux used to unpack downloads. The names match upstream builds, but a scan cannot confirm the bytes do.
- StabilityMatrix.Avalonia/Program.cs initializes Sentry with session tracking and a 100 percent trace sample rate unless you launch with --no-sentry or a debugger is attached. The DSN in the code is a public client key, not a secret. Other traffic is what the app is for: CivitAI and Hugging Face for models, GitHub and PyTorch for packages, and Lykos AI's CDN.
- 8 known advisories, none critical (4 high), all in docs/package-lock.json, the documentation site's build tooling (vite, postcss, nanoid, esbuild). The C# app's NuGet packages are not in a lockfile the scanner reads, so they were not checked.
- 8 workflows. cla.yml uses pull_request_target to run the contributor-assistant CLA action (tag v2.3.0) without checking out pull request code; none of the 12 third-party actions is pinned to a commit. Dependabot, licence and contributing guide present; no security policy or CodeQL. Release binaries are under Lykos AI's own licence agreement, not the AGPL.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | None found. |
| Install-time code | None: nothing runs at install beyond the package manager itself. |
| Committed binaries | 34 executable or compiled objects committed; listed under the raw findings. |
| CI workflows | 8 workflows. 1 uses pull_request_target, none check out the pull request head. 12 of 12 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 40 distinct hosts referenced from source; most often github.com, huggingface.co, civitai.com, cdn.lykos.ai. No URLs to bare IP addresses. |
| Known vulnerabilities | 8 advisories across 173 pinned packages: 0 critical, 4 high, 4 moderate, 0 low. docs/package-lock.json: 173 packages, 8 advisories. |
| Project hygiene | Has automated dependency updates, licence file, contributing guide. Missing security policy, CodeQL. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Committed binaries (34)
StabilityMatrix.Avalonia/Assets/macos-arm64/7zz: Mach-O, 6 MBStabilityMatrix/Assets/Python310/python310.dll: PE (Windows executable), 4 MBStabilityMatrix.Avalonia/Assets/linux-x64/7zzs: ELF, 4 MBStabilityMatrix/Assets/Python310/libcrypto-1_1.dll: PE (Windows executable), 3 MBStabilityMatrix/Assets/Python310/sqlite3.dll: PE (Windows executable), 2 MBStabilityMatrix.Avalonia/Assets/win-x64/7za.exe: PE (Windows executable), 1 MBStabilityMatrix/Assets/7za.exe: PE (Windows executable), 1 MBStabilityMatrix/Assets/Python310/unicodedata.pyd: PE (Windows executable), 1 MBStabilityMatrix/Assets/Python310/libssl-1_1.dll: PE (Windows executable), 705 KBStabilityMatrix/Assets/Python310/_decimal.pyd: PE (Windows executable), 255 KBStabilityMatrix/Assets/Python310/pyexpat.pyd: PE (Windows executable), 199 KBStabilityMatrix/Assets/Python310/_ssl.pyd: PE (Windows executable), 161 KBStabilityMatrix/Assets/Python310/_lzma.pyd: PE (Windows executable), 158 KBStabilityMatrix/Assets/Python310/_elementtree.pyd: PE (Windows executable), 128 KBStabilityMatrix/Assets/Python310/_ctypes.pyd: PE (Windows executable), 124 KBStabilityMatrix/Assets/Python310/python.exe: PE (Windows executable), 103 KBStabilityMatrix/Assets/Python310/pythonw.exe: PE (Windows executable), 102 KBStabilityMatrix/Assets/Python310/_sqlite3.pyd: PE (Windows executable), 99 KBStabilityMatrix/Assets/Python310/vcruntime140.dll: PE (Windows executable), 98 KBStabilityMatrix/Assets/Python310/_bz2.pyd: PE (Windows executable), 84 KBStabilityMatrix/Assets/Python310/_socket.pyd: PE (Windows executable), 79 KBStabilityMatrix/Assets/Python310/python3.dll: PE (Windows executable), 66 KBStabilityMatrix/Assets/Python310/_asyncio.pyd: PE (Windows executable), 65 KBStabilityMatrix/Assets/Python310/_hashlib.pyd: PE (Windows executable), 65 KB- and 10 more
Worst known vulnerabilities (8 of 8)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-28wg-ghj8-5hjv | high | nanoid@3.3.15 | nanoid: non-secure generators can loop indefinitely with negative size |
| GHSA-2v37-7h3g-55p8 | high | nanoid@3.3.15 | nanoid: custom generators can loop indefinitely when size is zero |
| GHSA-r28c-9q8g-f849 | high | postcss@8.5.16 | PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure |
| GHSA-fx2h-pf6j-xcff | high | vite@5.4.21 | vite: `server.fs.deny` bypass on Windows alternate paths |
| GHSA-67mh-4wv8-2f99 | moderate | esbuild@0.21.5 | esbuild enables any website to send any requests to the development server and read the response |
| GHSA-fxqj-rqcc-2cmp | moderate | postcss@8.5.16 | PostCSS: incomplete fix of GHSA-6g55-p6wh-862q - attacker-controlled sourceMappingURL reads arbitrary .map files when `f… |
| GHSA-4w7w-66w2-5vf9 | moderate | vite@5.4.21 | Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling |
| GHSA-v6wh-96g9-6wx3 | moderate | vite@5.4.21 | launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows |
Workflows worth a look
- .github/workflows/cla.yml: pull_request_target
By the numbers
| Stars | 8,865 |
|---|---|
| Forks | 606 |
| Contributors | 32 |
| Commits | 7,449 |
| Open issues | 162 |
| Open pull requests | 18 |
| Releases | 106 |
| Latest release | v2.16.4 |
| Licence | AGPL-3.0 |
| Main language | C# |
| Project age | 3 years |
| Last push | Oct 1, 2026 |
| Tracked files | 1,843 |
| Lines of code | 204.6K |
| Checkout size | 61 MB |
Lines by language: C# 192.7K, Markdown 6,204, JSON 2,517, CSS 1,131, YAML 1,119, Python 653.
Questions
Is Stability Matrix free?
Yes, it costs nothing to download and use. The source code is AGPL-3.0; the ready-made builds are released under Lykos AI's end-user licence agreement. The interfaces it installs are free open-source projects, and models from CivitAI and Hugging Face carry their own licences.
Which interfaces can Stability Matrix install?
ComfyUI, Stable Diffusion WebUI Forge, reForge and AMDGPU Forge, Automatic1111 and its DirectML fork, SD Web UI-UX, SD.Next, Fooocus and several Fooocus forks, SimpleSDXL, SwarmUI, VoltaML, InvokeAI, SDFX, Kohya's GUI, OneTrainer, FluxGym and CogVideo through CogStudio.
Can Stability Matrix use models I already have?
Yes. Drag existing model files into its Checkpoint Manager, or point it at your current folders, and it can look up CivitAI metadata and preview thumbnails for them. Every interface it installs is then wired to that one shared library.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
