swarm-advanced
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions to install the required tooling from the npm registry.
- Evidence:
npm install -g claude-flow@alphaandnpx claude-flow@alpha mcp startinSKILL.md. - These commands fetch the
claude-flowpackage from a well-known package registry to set up the orchestration environment. - [COMMAND_EXECUTION]: The orchestration patterns utilize tools designed to execute tasks and manage workflows across multiple agents.
- Evidence:
mcp__claude-flow__parallel_execute,mcp__claude-flow__task_orchestrate, andmcp__claude-flow__workflow_executeare used throughoutSKILL.mdto define and run agent tasks. - These tools are central to the skill's primary function of swarm coordination and allow the agent to delegate complex operations to specialized sub-agents.
- [INDIRECT_PROMPT_INJECTION]: The swarm architecture involves processing data gathered from external sources and sharing it between agents, creating a potential surface for indirect prompt injection.
- Ingestion points: External data enters the swarm context via
mcp__claude-flow__parallel_execute(performing web and academic searches) as seen in the Research Swarm pattern inSKILL.md. - Boundary markers: The documented patterns do not specify explicit delimiters or "ignore instructions" wrappers for the data passed between agents.
- Capability inventory: The swarm environment possesses capabilities for task execution (
parallel_execute), file management (memory_backup), and automated triggers (automation_setup). - Sanitization: There is no evidence of explicit sanitization or filtering of external content before it is processed by downstream agents (e.g., the Report Writer or Code Reviewer).
Audit Metadata