hive-mind-advanced
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted user input in the form of 'objectives' and 'task descriptions' which are then processed by a swarm of autonomous agents. This creates a potential surface where malicious instructions embedded in a task could attempt to influence the agent swarm's logic.
- Ingestion points: External data enters the system through the
objectiveparameter in thespawncommand and the task content increateTask. - Boundary markers: The instructions do not define specific delimiters or isolation prompts to separate user instructions from system coordination logic.
- Capability inventory: The system has the capability to execute shell commands (
npx), maintain persistent state (SQLite), and coordinate multiple specialized workers. - Sanitization: No explicit sanitization or validation of the input objective is described in the skill content.
- [EXTERNAL_DOWNLOADS]: The skill relies on the
npxpackage runner to execute various commands associated with theclaude-flowCLI. This involves fetching and executing code from the NPM registry. - Evidence: Commands such as
npx claude-flow hive-mind initandnpx claude-flow hive-mind spawnare used for core functionality. These resources are consistent with the identified vendor resources for the author. - [COMMAND_EXECUTION]: The skill documentation provides numerous examples of shell commands being executed to manage the lifecycle of the agent hive.
- Evidence: Execution of
npxfor initialization, swarm spawning, and session management.
Audit Metadata