flow-nexus-platform
Warn
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses
preandposthooks in its frontmatter to automatically execute shell commands when the skill is activated or completed. These commands change directories to/workspaces/ruvector/.claude/intelligenceand execute a Node.js script (cli.js) with the$FILEvariable as an argument. - [DYNAMIC_EXECUTION]: The skill provides tools like
mcp__flow-nexus__sandbox_executeandmcp__flow-nexus__sandbox_createthat allow for the execution of arbitrary code strings and the definition of startup scripts in various languages (JavaScript, Python) within sandbox environments. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process potentially untrusted data that could contain malicious instructions.
- Ingestion points: Challenge submissions via
mcp__flow-nexus__challenge_submit, application source code viamcp__flow-nexus__app_store_publish_app, and user profile updates. - Boundary markers: None identified in the instruction text to delimit external data from agent instructions.
- Capability inventory: The skill possesses broad capabilities, including arbitrary code execution (
sandbox_execute), file system operations (storage_upload,sandbox_upload), and application deployment (template_deploy). - Sanitization: There are no documented procedures for sanitizing or validating the input data before it is processed or executed.
- [COMMAND_EXECUTION]: The sandbox management features allow for the execution of arbitrary shell commands via the
run_commandsandstartup_scriptparameters during sandbox configuration.
Audit Metadata