skills/react/react/flow/Gen Agent Trust Hub

flow

Warn

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The instruction to run yarn flow $ARGUMENTS directly interpolates a user-controlled variable into a shell command. The absence of input sanitization or validation guidelines within the skill creates a risk of command injection through the use of shell metacharacters such as semicolons, pipes, or command substitution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 24, 2026, 10:51 AM
Security Audit — agent-trust-hub — flow