embeddings
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
npx claude-flowto run initialization, text embedding, and semantic search commands.- [EXTERNAL_DOWNLOADS]: Thenpxcommand downloads theclaude-flowpackage from the NPM registry if it is not already available.- [INDIRECT_PROMPT_INJECTION]:\n - Ingestion points: Data is ingested from
documents.jsonduring batch processing and from search queries.\n - Boundary markers: There are no boundary markers or instructions to disregard embedded commands in the ingested data.\n
- Capability inventory: The skill has the ability to read local files and execute shell commands.\n
- Sanitization: No input validation or sanitization mechanisms are described.- [DYNAMIC_EXECUTION]: The skill utilizes
sql.js, which involves the execution of WebAssembly (WASM) code for database operations.
Audit Metadata