agent-multi-repo-swarm
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMOBFUSCATIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [OBFUSCATION]: The skill employs a pervasive character substitution technique where the dollar sign ('$') is used in place of forward slashes ('/') and occasionally periods ('.') in file paths, URLs, and command-line arguments. Examples include '$dev$null' for '/dev/null', 'github.com$my-org$frontend' for 'github.com/my-org/frontend', and '.swarm$multi-repo.yml' for '.swarm/multi-repo.yml'. This obfuscation effectively conceals standard system paths and network locations from automated detection tools.
- [EXTERNAL_DOWNLOADS]: The skill frequently utilizes 'npx' to download and execute the 'ruv-swarm' package from the NPM registry during runtime. While this tool appears to be associated with the vendor, the dynamic execution of remote code without specific version pinning or integrity checks introduces a supply chain risk.
- [REMOTE_CODE_EXECUTION]: The use of 'npx ruv-swarm' across various orchestration commands constitutes remote code execution, as it fetches and runs scripts from an external package registry.
- [COMMAND_EXECUTION]: The skill automates complex cross-repository workflows by executing numerous shell commands, including 'gh repo clone' for cloning, 'gh api' for repository interaction, and 'npm install' for dependency management.
- [INDIRECT_PROMPT_INJECTION]: The orchestration workflows ingestion data from external GitHub repositories, such as repository metadata and the decoded contents of 'package.json' files. This data is then used as input for further commands, creating a potential surface for indirect prompt injection.
- Ingestion points: Fetches repository lists, metadata, and file contents (e.g., package.json) via GitHub CLI commands.
- Boundary markers: The instructions do not include explicit delimiters or warnings to ignore potentially malicious embedded instructions in the ingested data.
- Capability inventory: The skill has the capability to write files, clone repositories, install packages, and create pull requests.
- Sanitization: There is no evidence of sanitization or validation performed on the ingested repository data before it is used in automation steps.
Audit Metadata