aqe-ruflo

Warn

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx to execute the ruflo package, which triggers the download and execution of external code from the public NPM registry at runtime.
  • [COMMAND_EXECUTION]: Several shell commands are provided for the agent to execute, specifically npx ruflo doctor and npx ruflo discover-plugins, to manage orchestration environment state.
  • [REMOTE_CODE_EXECUTION]: The use of npx with external packages represents a remote code execution vector, as it fetches and runs logic from a third-party source without explicit version pinning or integrity verification.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 12:14 PM
Security Audit — agent-trust-hub — aqe-ruflo