performance-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous examples and instructions for the agent to execute shell commands using npx claude-flow. This includes analysis commands and optimization commands with the --fix flag that modify the environment.\n- [EXTERNAL_DOWNLOADS]: The use of npx to run the claude-flow utility implies that the agent may download and execute code from the npm registry if the package is not already cached.\n- [DYNAMIC_EXECUTION]: The skill contains a reference script template in JavaScript that demonstrates the use of child_process.exec to run shell commands and fs.writeFileSync to save reports. If an agent follows this template, it will be generating and executing code at runtime.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze data from swarm operations, such as task logs and agent communication. This creates a potential surface for indirect prompt injection where malicious data within those logs could attempt to manipulate the agent's performance recommendations or report generation.\n
  • Ingestion points: Processes swarm performance metrics, task execution results (via mcp__claude-flow__task_results), and agent communication delays.\n
  • Boundary markers: No specific delimiters or instructions to ignore embedded content within the analyzed logs are provided.\n
  • Capability inventory: Includes shell command execution (npx), file writing (fs.writeFileSync), and automated optimization (--fix).\n
  • Sanitization: The skill does not define methods for sanitizing or validating the performance data before it is processed by the AI.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:12 AM
Security Audit — agent-trust-hub — performance-analysis