skills/ruvnet/ruflo/agent-sandbox/Gen Agent Trust Hub

agent-sandbox

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's primary purpose is to execute code within isolated environments using the mcp__flow-nexus__sandbox_execute tool. This tool allows for running JavaScript, Python, and other languages inside E2B sandboxes.
  • [DYNAMIC_EXECUTION]: The skill facilitates the creation and execution of dynamic code blocks at runtime. This is a core feature of a development sandbox and is managed through structured tools like mcp__flow-nexus__sandbox_create and mcp__flow-nexus__sandbox_execute.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles potentially untrusted data through code execution and file uploads, creating a vulnerability surface for indirect injection.
  • Ingestion points: The code parameter in mcp__flow-nexus__sandbox_execute and the content parameter in mcp__flow-nexus__sandbox_upload are primary entry points for external data.
  • Boundary markers: The instructions do not define specific delimiters for untrusted data, though they emphasize the use of isolated environments.
  • Capability inventory: The skill provides capabilities for sandbox creation, code execution, file uploads/downloads, and environment management.
  • Sanitization: The skill instructions recommend quality standards such as "Secure environment variable management" and "security isolation" to mitigate risks associated with processing untrusted content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:37 AM
Security Audit — agent-trust-hub — agent-sandbox