flow-nexus-platform
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill enables the generation and execution of arbitrary code within isolated environments via tools such as
mcp__flow-nexus__sandbox_execute. This is a core feature of the platform for testing and running applications. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data that could potentially contain malicious instructions.
- Ingestion points: Data enters the system through tools like
mcp__flow-nexus__challenge_submit(solution code),mcp__flow-nexus__app_store_publish_app(application source code), andmcp__flow-nexus__seraphina_chat(user messages). - Boundary markers: There are no specific delimiters or warnings documented in the tools to help the AI distinguish between data and instructions.
- Capability inventory: The skill possesses capabilities to write files (
mcp__flow-nexus__sandbox_upload), execute code (mcp__flow-nexus__sandbox_execute), and deploy applications (mcp__flow-nexus__template_deploy). - Sanitization: The skill does not explicitly mention sanitization or validation logic for the content it processes.
- [COMMAND_EXECUTION]: The skill allows the execution of shell commands and script installation within sandbox environments using the
startup_scriptandrun_commandsparameters in thesandbox_createandsandbox_configuretools.
Audit Metadata