skills/boshu2/agentops/using-flywheel/Gen Agent Trust Hub

using-flywheel

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to download and run an installer from an external website (agent-flywheel.com).
  • Evidence: SKILL.md mentions a "single-curl install on a dedicated Ubuntu VPS" via the upstream wizard at agent-flywheel.com.
  • [REMOTE_CODE_EXECUTION]: The procedure involves executing a shell script downloaded directly from the internet onto a host machine.
  • Evidence: Step 1 in the Procedure section of SKILL.md describes a "single-curl install" from the agent-flywheel.com domain.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data generated by external agent swarms and factory runtime states.
  • Ingestion points: Flywheel runtime state including "bead graph", "Agent Mail threads", and "NTM pane truth" as described in SKILL.md.
  • Boundary markers: None detected. The skill instructions do not specify delimiters or warnings to ignore instructions embedded in the runtime state.
  • Capability inventory: The skill executes local shell scripts (scripts/validate.sh) and interacts with multiple worker runtimes (Claude Code, Codex CLI, Antigravity CLI).
  • Sanitization: Absent. The skill instructions prioritize "pane truth over roster claims" but do not define sanitization logic for the ingested prose or state data.
  • [COMMAND_EXECUTION]: The skill executes local shell scripts that chain to other components within the repository.
  • Evidence: scripts/validate.sh uses exec bash to run a heal.sh script located in the repository's skill-builder directory.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:34 AM
Security Audit — agent-trust-hub — using-flywheel