agent-topology-optimizer

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to ingest and process data from external files, which could contain malicious prompts.
  • Ingestion points: Data is loaded from files specified in the command arguments for workload profiles, constraints, and historical communication patterns.
  • Boundary markers: No explicit delimitation or 'ignore instructions' warnings are provided for the processed data.
  • Capability inventory: The skill includes shell command execution, neural model training/loading, and swarm management capabilities.
  • Sanitization: The skill lacks explicit sanitization or validation logic for external inputs.
  • [COMMAND_EXECUTION]: The skill uses npx claude-flow for its operational interface. This pattern executes shell commands using a package retrieved from the well-known npm registry.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — agent-topology-optimizer