flow-nexus-swarm

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines pre and post hooks in its YAML frontmatter that execute shell commands and node scripts when the skill is activated or finished. These commands are conditionally executed based on the presence of a specific local workspace directory (/workspaces/ruvector/.claude/intelligence).
  • [EXTERNAL_DOWNLOADS]: The documentation references the installation of the flow-nexus and claude-flow packages from the public NPM registry, which are the official tools for the platform described in the skill.
  • [DYNAMIC_EXECUTION]: The pre and post hooks execute a local Node.js script (cli.js) using the node runtime to handle intelligence modes during skill execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as task descriptions and workflow configurations, which serves as a potential surface for indirect prompt injection.
  • Ingestion points: The task parameter in mcp__flow-nexus__task_orchestrate and the steps array in mcp__flow-nexus__workflow_create in SKILL.md.
  • Boundary markers: None identified in the provided instructions.
  • Capability inventory: The skill utilizes subprocess execution through its hooks and interacts with external cloud orchestration APIs via its MCP tools.
  • Sanitization: No explicit sanitization or validation of the ingested task data is documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:38 AM
Security Audit — agent-trust-hub — flow-nexus-swarm