flow-nexus-swarm
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires installation of the
flow-nexusandclaude-flowpackages from the NPM registry. These are vendor-provided tools required for the orchestration platform to function. - [DYNAMIC_EXECUTION]: The platform supports specialized agents like 'Coder', which are explicitly described as being capable of code generation and implementation at runtime to fulfill tasks defined in workflows.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from task descriptions and workflow inputs which are then acted upon by AI agents with significant system capabilities.
- Ingestion points: Data enters the system via the
taskparameter inmcp__flow-nexus__task_orchestrateand theinput_dataobject inmcp__flow-nexus__workflow_executewithinSKILL.md. - Boundary markers: The skill does not define specific delimiters or instructions to prevent the agent from following commands embedded within the input data.
- Capability inventory: The skill can spawn new agents with varied capabilities (
mcp__flow-nexus__agent_spawn), orchestrate complex task sequences, and manage cloud-based execution streams. - Sanitization: There is no documentation or evidence of input sanitization to filter out potentially malicious instructions from the data before processing.
Audit Metadata