kg-traverse
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's documentation includes a CLI alternative that utilizes
npxto download the@claude-flow/clipackage from an external registry. - [REMOTE_CODE_EXECUTION]: The documented
npxcommand results in the execution of the downloaded package code on the host system. - [COMMAND_EXECUTION]: The skill requires access to the
Bashtool and provides shell commands for performing searches within the knowledge graph. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill retrieves data from a knowledge graph, including entity names and relationship details, using the
causal-edgeandhierarchical-recalltools. - Boundary markers: The instructions lack explicit delimiters or warnings to treat ingested graph content as untrusted data.
- Capability inventory: The skill utilizes
Bashand various database search tools to process and report on graph structures. - Sanitization: There is no evidence of sanitization or filtering of content retrieved from the knowledge graph nodes before it is synthesized into a report.
Audit Metadata