skills/ruvnet/ruflo/security-audit/Gen Agent Trust Hub

security-audit

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to dynamically fetch and execute the package @claude-flow/cli in SKILL.md, scripts/cve-remediate.sh, and scripts/security-scan.sh. The dependency is not pinned to a specific version or cryptographic hash, creating a potential risk of runtime supply-chain dependency manipulation.
  • [COMMAND_EXECUTION]: Shell script pipelines execute local command-line binaries and public npm registry utilities (npx, npm audit fix) to automate codebase security analyses, vulnerability tracking, and dependency remediations.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 11:37 AM
Security Audit — agent-trust-hub — security-audit