skills/ruvnet/ruflo/agent-swarm-pr/Gen Agent Trust Hub

agent-swarm-pr

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands and the GitHub CLI (gh) to perform pull request operations, such as fetching diffs, viewing metadata, and posting comments. These operations are core to the skill's functionality.
  • [EXTERNAL_DOWNLOADS]: The skill uses npx ruv-swarm to fetch and run the swarm management utility. This package is provided by the identified vendor and is used for its intended orchestration purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from pull request descriptions, comments, and labels to drive agent behavior. (1) Ingestion points: PR metadata and comments are captured via gh pr view and GitHub webhook payloads in SKILL.md. (2) Boundary markers: None explicitly defined in the provided instruction patterns. (3) Capability inventory: The skill has access to GitHub PR management tools (mcp__github__), swarm orchestration tools (mcp__claude-flow__), and local shell execution (Bash). (4) Sanitization: Not demonstrated in the skill's integration examples.
  • [DYNAMIC_EXECUTION]: The webhook-handler.js example uses execSync to dynamically execute swarm commands based on incoming GitHub webhook events. While interpolation of external data into shell commands is present in the example, it is illustrative of integration patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — agent-swarm-pr