skills/ruvnet/ruview/swarm-advanced/Gen Agent Trust Hub

swarm-advanced

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions to install the required tooling from the npm registry.
  • Evidence: npm install -g claude-flow@alpha and npx claude-flow@alpha mcp start in SKILL.md.
  • These commands fetch the claude-flow package from a well-known package registry to set up the orchestration environment.
  • [COMMAND_EXECUTION]: The orchestration patterns utilize tools designed to execute tasks and manage workflows across multiple agents.
  • Evidence: mcp__claude-flow__parallel_execute, mcp__claude-flow__task_orchestrate, and mcp__claude-flow__workflow_execute are used throughout SKILL.md to define and run agent tasks.
  • These tools are central to the skill's primary function of swarm coordination and allow the agent to delegate complex operations to specialized sub-agents.
  • [INDIRECT_PROMPT_INJECTION]: The swarm architecture involves processing data gathered from external sources and sharing it between agents, creating a potential surface for indirect prompt injection.
  • Ingestion points: External data enters the swarm context via mcp__claude-flow__parallel_execute (performing web and academic searches) as seen in the Research Swarm pattern in SKILL.md.
  • Boundary markers: The documented patterns do not specify explicit delimiters or "ignore instructions" wrappers for the data passed between agents.
  • Capability inventory: The swarm environment possesses capabilities for task execution (parallel_execute), file management (memory_backup), and automated triggers (automation_setup).
  • Sanitization: There is no evidence of explicit sanitization or filtering of external content before it is processed by downstream agents (e.g., the Report Writer or Code Reviewer).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:55 AM
Security Audit — agent-trust-hub — swarm-advanced