performance-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous examples and instructions for the agent to execute shell commands using
npx claude-flow. This includes analysis commands and optimization commands with the--fixflag that modify the environment.\n- [EXTERNAL_DOWNLOADS]: The use ofnpxto run theclaude-flowutility implies that the agent may download and execute code from the npm registry if the package is not already cached.\n- [DYNAMIC_EXECUTION]: The skill contains a reference script template in JavaScript that demonstrates the use ofchild_process.execto run shell commands andfs.writeFileSyncto save reports. If an agent follows this template, it will be generating and executing code at runtime.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze data from swarm operations, such as task logs and agent communication. This creates a potential surface for indirect prompt injection where malicious data within those logs could attempt to manipulate the agent's performance recommendations or report generation.\n - Ingestion points: Processes swarm performance metrics, task execution results (via
mcp__claude-flow__task_results), and agent communication delays.\n - Boundary markers: No specific delimiters or instructions to ignore embedded content within the analyzed logs are provided.\n
- Capability inventory: Includes shell command execution (
npx), file writing (fs.writeFileSync), and automated optimization (--fix).\n - Sanitization: The skill does not define methods for sanitizing or validating the performance data before it is processed by the AI.
Audit Metadata