ruflo
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The documentation for the skill and several plugins recommends a highly insecure installation pattern by piping a remote script to bash:
curl -fsSL https://cdn.jsdelivr.net/gh/ruvnet/ruflo@main/scripts/install.sh | bash. The source repository belongs to an untrusted third party and is not affiliated with the skill author. - [PRIVILEGE_ESCALATION]: The federation guide instructs users to run multiple network and system configuration commands with
sudo(e.g.,sudo wg-quick up,sudo nft,sudo pfctl), which can lead to agents acquiring root-level permissions. - [EXTERNAL_DOWNLOADS]: The skill frequently uses
npxto download and execute tools from non-trusted external sources (e.g.,npx ruv-swarm,npx agentic-flow) and references dependencies likenumpy,scipy, andtensorflowto be installed in sandboxed environments without whitelisting. - [COMMAND_EXECUTION]: Many specialized agents in the skill are explicitly configured to use the
Bashtool for arbitrary shell execution, and the platform provides tools likemcp__flow-nexus__sandbox_executefor running code in isolated environments. - [INDIRECT_PROMPT_INJECTION]: The swarm architecture enables agents such as
repo-architectandsync-coordinatorto read untrusted codebase files and subsequently perform outbound operations like pushing files to GitHub repositories, which creates a significant surface for data exfiltration or unauthorized code modification via indirect injections.
Recommendations
- HIGH: Downloads and executes remote code from: https://cdn.jsdelivr.net/gh/ruvnet/claude-flow@main/scripts/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata