flow-nexus-neural
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Flow Nexus MCP server using
npx flow-nexus@latest, which downloads and executes code from the official NPM registry. - [COMMAND_EXECUTION]: The
preandposthooks execute shell commands and launch a Node.js CLI script located at/workspaces/ruvector/.claude/intelligence/cli.js. This functionality is part of the skill's integration with its management component. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided inputs and model configurations through various MCP tools. * Ingestion points: The
mcp__flow-nexus__neural_predicttool accepts array-based input data, andmcp__flow-nexus__neural_trainaccepts model architecture and training configurations. * Boundary markers: No specific delimiters or safety warnings for embedded instructions are provided in the example usage. * Capability inventory: The skill possesses the ability to execute shell commands via platform hooks and perform network operations through the Flow Nexus MCP server. * Sanitization: There is no evidence of explicit sanitization or validation of the input data before processing.
Audit Metadata