flow-nexus-platform

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill enables the generation and execution of arbitrary code within isolated environments via tools such as mcp__flow-nexus__sandbox_execute. This is a core feature of the platform for testing and running applications.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data that could potentially contain malicious instructions.
  • Ingestion points: Data enters the system through tools like mcp__flow-nexus__challenge_submit (solution code), mcp__flow-nexus__app_store_publish_app (application source code), and mcp__flow-nexus__seraphina_chat (user messages).
  • Boundary markers: There are no specific delimiters or warnings documented in the tools to help the AI distinguish between data and instructions.
  • Capability inventory: The skill possesses capabilities to write files (mcp__flow-nexus__sandbox_upload), execute code (mcp__flow-nexus__sandbox_execute), and deploy applications (mcp__flow-nexus__template_deploy).
  • Sanitization: The skill does not explicitly mention sanitization or validation logic for the content it processes.
  • [COMMAND_EXECUTION]: The skill allows the execution of shell commands and script installation within sandbox environments using the startup_script and run_commands parameters in the sandbox_create and sandbox_configure tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:12 AM
Security Audit — agent-trust-hub — flow-nexus-platform