using-flywheel
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to download and run an installer from an external website (agent-flywheel.com).
- Evidence: SKILL.md mentions a "single-curl install on a dedicated Ubuntu VPS" via the upstream wizard at
agent-flywheel.com. - [REMOTE_CODE_EXECUTION]: The procedure involves executing a shell script downloaded directly from the internet onto a host machine.
- Evidence: Step 1 in the Procedure section of SKILL.md describes a "single-curl install" from the
agent-flywheel.comdomain. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data generated by external agent swarms and factory runtime states.
- Ingestion points: Flywheel runtime state including "bead graph", "Agent Mail threads", and "NTM pane truth" as described in SKILL.md.
- Boundary markers: None detected. The skill instructions do not specify delimiters or warnings to ignore instructions embedded in the runtime state.
- Capability inventory: The skill executes local shell scripts (
scripts/validate.sh) and interacts with multiple worker runtimes (Claude Code, Codex CLI, Antigravity CLI). - Sanitization: Absent. The skill instructions prioritize "pane truth over roster claims" but do not define sanitization logic for the ingested prose or state data.
- [COMMAND_EXECUTION]: The skill executes local shell scripts that chain to other components within the repository.
- Evidence:
scripts/validate.shusesexec bashto run aheal.shscript located in the repository'sskill-builderdirectory.
Audit Metadata