swarm-orchestration

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and executes an external package, @claude-flow/cli, which is downloaded from the NPM registry at runtime.
  • Evidence: Multiple npx @claude-flow/cli commands found in SKILL.md, scripts/swarm-monitor.sh, and scripts/swarm-start.sh.
  • [REMOTE_CODE_EXECUTION]: The use of npx facilitates the download and immediate execution of remote code from a third-party registry.
  • Evidence: npx @claude-flow/cli usage across all skill scripts and instruction files.
  • [COMMAND_EXECUTION]: The skill is designed to execute shell commands to manage agent swarms and tasks.
  • Evidence: Definitions for swarm init, hooks route, agent spawn, and task orchestrate in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions define command templates that interpolate untrusted task descriptions directly into shell commands, creating a potential injection surface.
  • Ingestion points: The --task parameter in SKILL.md (e.g., npx @claude-flow/cli hooks route --task "[task description]").
  • Boundary markers: Absent; there are no instructions to the agent to sanitize or escape the input before execution.
  • Capability inventory: Shell command execution via npx.
  • Sanitization: Absent; the templates suggest direct placement of user input within command arguments, which can be bypassed with shell metacharacters like backticks or semicolons.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — swarm-orchestration