flow-nexus-platform

Warn

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses pre and post hooks in its frontmatter to automatically execute shell commands when the skill is activated or completed. These commands change directories to /workspaces/ruvector/.claude/intelligence and execute a Node.js script (cli.js) with the $FILE variable as an argument.
  • [DYNAMIC_EXECUTION]: The skill provides tools like mcp__flow-nexus__sandbox_execute and mcp__flow-nexus__sandbox_create that allow for the execution of arbitrary code strings and the definition of startup scripts in various languages (JavaScript, Python) within sandbox environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process potentially untrusted data that could contain malicious instructions.
  • Ingestion points: Challenge submissions via mcp__flow-nexus__challenge_submit, application source code via mcp__flow-nexus__app_store_publish_app, and user profile updates.
  • Boundary markers: None identified in the instruction text to delimit external data from agent instructions.
  • Capability inventory: The skill possesses broad capabilities, including arbitrary code execution (sandbox_execute), file system operations (storage_upload, sandbox_upload), and application deployment (template_deploy).
  • Sanitization: There are no documented procedures for sanitizing or validating the input data before it is processed or executed.
  • [COMMAND_EXECUTION]: The sandbox management features allow for the execution of arbitrary shell commands via the run_commands and startup_script parameters during sandbox configuration.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 18, 2026, 05:38 AM
Security Audit — agent-trust-hub — flow-nexus-platform