Pair Programming
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs users to install the
claude-flowCLI tool globally using npm (npm install -g claude-flow@alpha). This tool is a primary requirement for the skill's functionality and is hosted on a well-known service. - [COMMAND_EXECUTION]: The skill heavily utilizes shell commands via the
claude-flowCLI to manage development sessions, execute test suites, perform Git operations (such as commits, branching, and stashing), and run performance profiling. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project files and source code, creating a surface for indirect prompt injection where malicious instructions hidden in the code could attempt to influence the AI's behavior.
- Ingestion points: The agent ingests local source code files, configuration files, and git history during review, implementation, and refactoring tasks.
- Boundary markers: There are no specific delimiters or 'ignore embedded instructions' warnings mentioned in the instructions to prevent the agent from obeying instructions found within the project files.
- Capability inventory: The skill possesses extensive capabilities including file writing (
/implement), code modification (/refactor), command execution for testing (/test,/perf), and version control operations (/commit). - Sanitization: The documentation does not describe any specific sanitization, validation, or escaping of the code content before it is interpolated into the agent's context.
Audit Metadata