flow-nexus-swarm
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMOBFUSCATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [OBFUSCATION]: The skill uses character substitution in its support section to mask URLs, replacing path separators (/) with dollar signs ($). This technique is frequently used to bypass simple text-based security filters.
- [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for executing workflows that ingest external data, creating a potential surface for indirect prompt injection.
- Ingestion points: The
input_dataparameter in themcp__flow-nexus__workflow_executefunction in SKILL.md. - Boundary markers: No delimiters or "ignore embedded instructions" warnings are specified in the prompt templates.
- Capability inventory: The skill has extensive capabilities including spawning agents (
agent_spawn), orchestrating tasks (task_orchestrate), creating workflows (workflow_create), and listing files created during execution (execution_files_list). - Sanitization: No evidence of input validation or sanitization is present in the skill instructions.
- [EXTERNAL_DOWNLOADS]: The skill requires the installation and execution of the
flow-nexuspackage from the npm registry for its core functionality. - Evidence: Commands
npm install -g flow-nexus@latestandnpx flow-nexus@latestare used for setup and authentication in SKILL.md.
Audit Metadata