sparc-methodology
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documents the use of
npxto run theclaude-flowutility. This package is the official framework provided by the author and is required for the methodology to function.- [COMMAND_EXECUTION]: The methodology relies on shell commands to activate various modes, such asnpx claude-flow sparc runandnpx claude-flow@alpha hooks. These are standard operational commands for this development framework.- [INDIRECT_PROMPT_INJECTION]: Theresearchermode fetches data from external web sources, creating an attack surface for indirect prompt injection.\n- Ingestion points: WebSearch and WebFetch capabilities described in SKILL.md.\n- Boundary markers: Not explicitly defined in the methodology description.\n- Capability inventory: Includes file modification (coder mode), agent spawning (orchestrator mode), and network access.\n- Sanitization: No specific sanitization methods for external data are detailed in this skill.
Audit Metadata