sparc-methodology

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documents the use of npx to run the claude-flow utility. This package is the official framework provided by the author and is required for the methodology to function.- [COMMAND_EXECUTION]: The methodology relies on shell commands to activate various modes, such as npx claude-flow sparc run and npx claude-flow@alpha hooks. These are standard operational commands for this development framework.- [INDIRECT_PROMPT_INJECTION]: The researcher mode fetches data from external web sources, creating an attack surface for indirect prompt injection.\n- Ingestion points: WebSearch and WebFetch capabilities described in SKILL.md.\n- Boundary markers: Not explicitly defined in the methodology description.\n- Capability inventory: Includes file modification (coder mode), agent spawning (orchestrator mode), and network access.\n- Sanitization: No specific sanitization methods for external data are detailed in this skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:38 AM
Security Audit — agent-trust-hub — sparc-methodology