security-audit
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npxto dynamically fetch and execute the package@claude-flow/cliinSKILL.md,scripts/cve-remediate.sh, andscripts/security-scan.sh. The dependency is not pinned to a specific version or cryptographic hash, creating a potential risk of runtime supply-chain dependency manipulation. - [COMMAND_EXECUTION]: Shell script pipelines execute local command-line binaries and public npm registry utilities (
npx,npm audit fix) to automate codebase security analyses, vulnerability tracking, and dependency remediations.
Audit Metadata