flow-nexus-neural

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Flow Nexus MCP server using npx flow-nexus@latest, which downloads and executes code from the official NPM registry.
  • [COMMAND_EXECUTION]: The pre and post hooks execute shell commands and launch a Node.js CLI script located at /workspaces/ruvector/.claude/intelligence/cli.js. This functionality is part of the skill's integration with its management component.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided inputs and model configurations through various MCP tools. * Ingestion points: The mcp__flow-nexus__neural_predict tool accepts array-based input data, and mcp__flow-nexus__neural_train accepts model architecture and training configurations. * Boundary markers: No specific delimiters or safety warnings for embedded instructions are provided in the example usage. * Capability inventory: The skill possesses the ability to execute shell commands via platform hooks and perform network operations through the Flow Nexus MCP server. * Sanitization: There is no evidence of explicit sanitization or validation of the input data before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:38 AM
Security Audit — agent-trust-hub — flow-nexus-neural