migrate-create
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation includes an alternative command execution utilizing
npx @claude-flow/cli@latest, which fetches and runs external code from the public npm registry at runtime, introducing potential supply chain risk from unverified software sources. - [INDIRECT_PROMPT_INJECTION]: The skill accepts user-controlled data via the
<name>parameter to determine file structure and output locations. - Ingestion points: The
<name>argument provided during skill invocation. - Boundary markers: Absent; no boundary definitions or instructions to ignore embedded commands are present.
- Capability inventory: Employs
WriteandBashtools capable of creating code files and performing system tasks. - Sanitization: Absent; there is no validation or escaping performed on the parameter before it is integrated into filenames and templates.
Audit Metadata