skills/ruvnet/ruflo/market-ingest/Gen Agent Trust Hub

market-ingest

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides a CLI alternative command using npx @claude-flow/cli@latest. This instructs the system to download the latest version of the @claude-flow/cli package from the NPM registry.
  • [COMMAND_EXECUTION]: The skill requests access to the Bash tool and provides shell commands for data management tasks.
  • [DYNAMIC_EXECUTION]: The use of npx to fetch and execute code dynamically at runtime is a potential vector for supply chain attacks, especially when using the @latest tag which bypasses version pinning.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from untrusted external sources like REST APIs and CSV files.
  • Ingestion points: Step 1 in SKILL.md explicitly mentions fetching data from REST APIs and CSV files.
  • Boundary markers: There are no explicit boundary markers or instructions to the agent to ignore embedded commands within the ingested data.
  • Capability inventory: The skill utilizes Bash, memory storage tools (mcp__plugin_ruflo-core_ruflo__memory_store, mcp__plugin_ruflo-core_ruflo__memory_search), and HNSW indexing tools (mcp__plugin_ruflo-core_ruflo__ruvllm_hnsw_create, mcp__plugin_ruflo-core_ruflo__ruvllm_hnsw_add).
  • Sanitization: While the skill performs mathematical normalization on price and volume data (which acts as a form of sanitization for numerical values), it lacks validation for non-numerical content that may be included in the market data source.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — market-ingest