hive-mind-advanced
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill defines
preandpostshell hooks in the YAML frontmatter. These hooks perform environment checks and run a local Node.js script (cli.js) within a vendor-specific directory (/workspaces/ruvector/.claude/intelligence). - Evidence: The hooks use the pattern
INTELLIGENCE_MODE=treatment node cli.js pre-edit "$FILE"andINTELLIGENCE_MODE=treatment node cli.js post-edit "$FILE" "true". - Risk: If the
$FILEvariable (representing the active filename) is not properly sanitized by the platform, it could potentially allow for shell command injection if a malicious file name is processed. - [REMOTE_CODE_EXECUTION]: The skill's documentation and examples instruct the user to execute commands using
npx claude-flow, which downloads and executes packages from the NPM registry at runtime. - Evidence: Commands such as
npx claude-flow hive-mind initandnpx claude-flow hive-mind spawnare provided throughout the skill instructions. - Risk:
npxfetches and executes code from the NPM registry at runtime, which is an external and remote source of executable code. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to coordinate multiple specialized agents based on user-provided objectives, creating a surface for indirect prompt injection where malicious instructions could be embedded in data.
- Ingestion points: The skill ingests high-level "objectives" and "task descriptions" to coordinate workers, and the
pre/posthooks process the content of active files. - Boundary markers: There are no specific delimiters or "ignore" instructions present to separate the system logic from untrusted input data.
- Capability inventory: The system has significant capabilities including shell command execution (via hooks), persistent memory management (SQLite), and the ability to spawn and direct multiple sub-agents.
- Sanitization: No evidence of sanitization or validation logic for the external input data is provided in the skill manifest.
Audit Metadata