skills/ruvnet/ruflo/market-pattern/Gen Agent Trust Hub

market-pattern

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to run npx @claude-flow/cli@latest to search and store patterns. Executing unpinned packages from external repositories at runtime creates a vulnerability to supply chain attacks or package hijacking.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an injection surface through data ingestion pipelines.
  • Ingestion points: Loads external OHLCV market data via mcp__plugin_ruflo-core_ruflo__memory_search from the market-data namespace in SKILL.md.
  • Boundary markers: Absent. There are no boundary delimiters or warnings instructing the agent to ignore prompt instructions embedded in the market data.
  • Capability inventory: The skill has access to the powerful Bash tool as defined in the allowed-tools metadata field.
  • Sanitization: Absent. The data is parsed and processed directly without validation or sanitization routines.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — market-pattern