agent-coordinator-swarm-init
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses the
npxcommand in bothpreandposthooks to download and execute theclaude-flow@alphapackage from the npm registry at runtime. - [REMOTE_CODE_EXECUTION]: By invoking
npx claude-flow@alpha, the skill performs remote code execution by fetching code from a public package registry and running it within the execution environment. - [INDIRECT_PROMPT_INJECTION]: The skill incorporates an attack surface for indirect prompt injection by searching and potentially processing data from a shared memory namespace ('coordination') which can be modified by other agents or processes.
- Ingestion points: The
npx claude-flow@alpha memory search "swarm/*" --namespace coordinationcommand in theprehook reads data from a shared memory store. - Boundary markers: None are present to distinguish between trusted instructions and untrusted data retrieved from memory.
- Capability inventory: The skill has the capability to execute shell commands via
npxand write to the file system or memory state. - Sanitization: There is no evidence of sanitization or validation of the data retrieved from the shared coordination memory before it is processed.
Audit Metadata