agent-coordinator-swarm-init

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses the npx command in both pre and post hooks to download and execute the claude-flow@alpha package from the npm registry at runtime.
  • [REMOTE_CODE_EXECUTION]: By invoking npx claude-flow@alpha, the skill performs remote code execution by fetching code from a public package registry and running it within the execution environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill incorporates an attack surface for indirect prompt injection by searching and potentially processing data from a shared memory namespace ('coordination') which can be modified by other agents or processes.
  • Ingestion points: The npx claude-flow@alpha memory search "swarm/*" --namespace coordination command in the pre hook reads data from a shared memory store.
  • Boundary markers: None are present to distinguish between trusted instructions and untrusted data retrieved from memory.
  • Capability inventory: The skill has the capability to execute shell commands via npx and write to the file system or memory state.
  • Sanitization: There is no evidence of sanitization or validation of the data retrieved from the shared coordination memory before it is processed.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 11:37 AM
Security Audit — agent-trust-hub — agent-coordinator-swarm-init