market-pattern
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to run
npx @claude-flow/cli@latestto search and store patterns. Executing unpinned packages from external repositories at runtime creates a vulnerability to supply chain attacks or package hijacking. - [INDIRECT_PROMPT_INJECTION]: The skill presents an injection surface through data ingestion pipelines.
- Ingestion points: Loads external OHLCV market data via
mcp__plugin_ruflo-core_ruflo__memory_searchfrom themarket-datanamespace in SKILL.md. - Boundary markers: Absent. There are no boundary delimiters or warnings instructing the agent to ignore prompt instructions embedded in the market data.
- Capability inventory: The skill has access to the powerful
Bashtool as defined in theallowed-toolsmetadata field. - Sanitization: Absent. The data is parsed and processed directly without validation or sanitization routines.
Audit Metadata