market-ingest
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides a CLI alternative command using
npx @claude-flow/cli@latest. This instructs the system to download the latest version of the@claude-flow/clipackage from the NPM registry. - [COMMAND_EXECUTION]: The skill requests access to the
Bashtool and provides shell commands for data management tasks. - [DYNAMIC_EXECUTION]: The use of
npxto fetch and execute code dynamically at runtime is a potential vector for supply chain attacks, especially when using the@latesttag which bypasses version pinning. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from untrusted external sources like REST APIs and CSV files.
- Ingestion points: Step 1 in
SKILL.mdexplicitly mentions fetching data from REST APIs and CSV files. - Boundary markers: There are no explicit boundary markers or instructions to the agent to ignore embedded commands within the ingested data.
- Capability inventory: The skill utilizes
Bash, memory storage tools (mcp__plugin_ruflo-core_ruflo__memory_store,mcp__plugin_ruflo-core_ruflo__memory_search), and HNSW indexing tools (mcp__plugin_ruflo-core_ruflo__ruvllm_hnsw_create,mcp__plugin_ruflo-core_ruflo__ruvllm_hnsw_add). - Sanitization: While the skill performs mathematical normalization on price and volume data (which acts as a form of sanitization for numerical values), it lacks validation for non-numerical content that may be included in the market data source.
Audit Metadata