swarm-advanced

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive documentation and patterns for distributed research, development, and testing using the Claude Flow framework.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of the claude-flow package from the NPM registry and links to documentation on GitHub. These resources are official vendor components and are documented neutrally.
  • Evidence: npm install -g claude-flow@alpha and https://github.com/ruvnet/claude-flow.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines patterns that ingest external data, such as web search results and codebases, for analysis by specialized agents.
  • Ingestion points: The research swarm uses web-search and content-extraction capabilities in SKILL.md.
  • Boundary markers: The provided examples do not explicitly define boundary markers for external data ingestion.
  • Capability inventory: The skill spawns agents with capabilities including web-search, api interaction, and database access, and utilizes CLI commands via npx.
  • Sanitization: No explicit sanitization or validation logic is shown in the orchestration examples, representing a typical vulnerability surface for indirect injection that is managed by the underlying platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:12 AM
Security Audit — agent-trust-hub — swarm-advanced