hive-mind-advanced

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines pre and post shell hooks in the YAML frontmatter. These hooks perform environment checks and run a local Node.js script (cli.js) within a vendor-specific directory (/workspaces/ruvector/.claude/intelligence).
  • Evidence: The hooks use the pattern INTELLIGENCE_MODE=treatment node cli.js pre-edit "$FILE" and INTELLIGENCE_MODE=treatment node cli.js post-edit "$FILE" "true".
  • Risk: If the $FILE variable (representing the active filename) is not properly sanitized by the platform, it could potentially allow for shell command injection if a malicious file name is processed.
  • [REMOTE_CODE_EXECUTION]: The skill's documentation and examples instruct the user to execute commands using npx claude-flow, which downloads and executes packages from the NPM registry at runtime.
  • Evidence: Commands such as npx claude-flow hive-mind init and npx claude-flow hive-mind spawn are provided throughout the skill instructions.
  • Risk: npx fetches and executes code from the NPM registry at runtime, which is an external and remote source of executable code.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to coordinate multiple specialized agents based on user-provided objectives, creating a surface for indirect prompt injection where malicious instructions could be embedded in data.
  • Ingestion points: The skill ingests high-level "objectives" and "task descriptions" to coordinate workers, and the pre/post hooks process the content of active files.
  • Boundary markers: There are no specific delimiters or "ignore" instructions present to separate the system logic from untrusted input data.
  • Capability inventory: The system has significant capabilities including shell command execution (via hooks), persistent memory management (SQLite), and the ability to spawn and direct multiple sub-agents.
  • Sanitization: No evidence of sanitization or validation logic for the external input data is provided in the skill manifest.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:39 AM
Security Audit — agent-trust-hub — hive-mind-advanced