swarm-advanced
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive documentation and patterns for distributed research, development, and testing using the Claude Flow framework.
- [EXTERNAL_DOWNLOADS]: The skill references the installation of the
claude-flowpackage from the NPM registry and links to documentation on GitHub. These resources are official vendor components and are documented neutrally. - Evidence:
npm install -g claude-flow@alphaandhttps://github.com/ruvnet/claude-flow. - [INDIRECT_PROMPT_INJECTION]: The skill defines patterns that ingest external data, such as web search results and codebases, for analysis by specialized agents.
- Ingestion points: The research swarm uses
web-searchandcontent-extractioncapabilities inSKILL.md. - Boundary markers: The provided examples do not explicitly define boundary markers for external data ingestion.
- Capability inventory: The skill spawns agents with capabilities including
web-search,apiinteraction, anddatabaseaccess, and utilizes CLI commands vianpx. - Sanitization: No explicit sanitization or validation logic is shown in the orchestration examples, representing a typical vulnerability surface for indirect injection that is managed by the underlying platform.
Audit Metadata