skills/ruvnet/ruflo/flow-nexus-swarm/Gen Agent Trust Hub

flow-nexus-swarm

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMOBFUSCATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [OBFUSCATION]: The skill uses character substitution in its support section to mask URLs, replacing path separators (/) with dollar signs ($). This technique is frequently used to bypass simple text-based security filters.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for executing workflows that ingest external data, creating a potential surface for indirect prompt injection.
  • Ingestion points: The input_data parameter in the mcp__flow-nexus__workflow_execute function in SKILL.md.
  • Boundary markers: No delimiters or "ignore embedded instructions" warnings are specified in the prompt templates.
  • Capability inventory: The skill has extensive capabilities including spawning agents (agent_spawn), orchestrating tasks (task_orchestrate), creating workflows (workflow_create), and listing files created during execution (execution_files_list).
  • Sanitization: No evidence of input validation or sanitization is present in the skill instructions.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation and execution of the flow-nexus package from the npm registry for its core functionality.
  • Evidence: Commands npm install -g flow-nexus@latest and npx flow-nexus@latest are used for setup and authentication in SKILL.md.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — flow-nexus-swarm