flow-nexus-swarm
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill defines
preandposthooks in its YAML frontmatter that execute shell commands andnodescripts when the skill is activated or finished. These commands are conditionally executed based on the presence of a specific local workspace directory (/workspaces/ruvector/.claude/intelligence). - [EXTERNAL_DOWNLOADS]: The documentation references the installation of the
flow-nexusandclaude-flowpackages from the public NPM registry, which are the official tools for the platform described in the skill. - [DYNAMIC_EXECUTION]: The
preandposthooks execute a local Node.js script (cli.js) using thenoderuntime to handle intelligence modes during skill execution. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as task descriptions and workflow configurations, which serves as a potential surface for indirect prompt injection.
- Ingestion points: The
taskparameter inmcp__flow-nexus__task_orchestrateand thestepsarray inmcp__flow-nexus__workflow_createinSKILL.md. - Boundary markers: None identified in the provided instructions.
- Capability inventory: The skill utilizes subprocess execution through its hooks and interacts with external cloud orchestration APIs via its MCP tools.
- Sanitization: No explicit sanitization or validation of the ingested task data is documented.
Audit Metadata