skills/ruvnet/ruflo/kg-traverse/Gen Agent Trust Hub

kg-traverse

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's documentation includes a CLI alternative that utilizes npx to download the @claude-flow/cli package from an external registry.
  • [REMOTE_CODE_EXECUTION]: The documented npx command results in the execution of the downloaded package code on the host system.
  • [COMMAND_EXECUTION]: The skill requires access to the Bash tool and provides shell commands for performing searches within the knowledge graph.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill retrieves data from a knowledge graph, including entity names and relationship details, using the causal-edge and hierarchical-recall tools.
  • Boundary markers: The instructions lack explicit delimiters or warnings to treat ingested graph content as untrusted data.
  • Capability inventory: The skill utilizes Bash and various database search tools to process and report on graph structures.
  • Sanitization: There is no evidence of sanitization or filtering of content retrieved from the knowledge graph nodes before it is synthesized into a report.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — kg-traverse