swarm-orchestration
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references and executes an external package,
@claude-flow/cli, which is downloaded from the NPM registry at runtime. - Evidence: Multiple
npx @claude-flow/clicommands found inSKILL.md,scripts/swarm-monitor.sh, andscripts/swarm-start.sh. - [REMOTE_CODE_EXECUTION]: The use of
npxfacilitates the download and immediate execution of remote code from a third-party registry. - Evidence:
npx @claude-flow/cliusage across all skill scripts and instruction files. - [COMMAND_EXECUTION]: The skill is designed to execute shell commands to manage agent swarms and tasks.
- Evidence: Definitions for
swarm init,hooks route,agent spawn, andtask orchestrateinSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill instructions define command templates that interpolate untrusted task descriptions directly into shell commands, creating a potential injection surface.
- Ingestion points: The
--taskparameter inSKILL.md(e.g.,npx @claude-flow/cli hooks route --task "[task description]"). - Boundary markers: Absent; there are no instructions to the agent to sanitize or escape the input before execution.
- Capability inventory: Shell command execution via
npx. - Sanitization: Absent; the templates suggest direct placement of user input within command arguments, which can be bypassed with shell metacharacters like backticks or semicolons.
Audit Metadata