nextflow

Fail

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructions include installing Nextflow and nf-test by downloading and piping shell scripts directly into Bash. These scripts originate from official distribution domains (get.nextflow.io and get.nf-test.com).
  • [EXTERNAL_DOWNLOADS]: The skill manages dependencies and pipeline code through official channels including pip, conda, and Nextflow's built-in repository fetching mechanism.
  • [PRIVILEGE_ESCALATION]: Setup steps include the use of sudo to move the Nextflow binary to a system path (/usr/local/bin/), which is a standard administrative task for global installation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data like CSV samplesheets and executes Nextflow scripts. It provides instructions for the agent to validate input formats and harmonize identifiers as basic security measures. Mandatory Evidence: Ingestion points include samplesheets and pipeline scripts; boundary markers are present in the form of validation instructions; capabilities include shell execution and file writing; sanitization is performed by the Nextflow runtime isolation.
  • [DYNAMIC_EXECUTION]: Nextflow functions as a dynamic execution engine that generates and runs scripts based on workflow definitions. The skill also describes using eval() in modules to capture tool versions.
  • [COMMAND_EXECUTION]: The skill makes extensive use of CLI commands for running pipelines, linting code, and managing environments.
Recommendations
  • HIGH: Downloads and executes remote code from: https://get.nextflow.io - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — nextflow