flow-nexus-platform

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents and provides access to tools designed for executing code within isolated sandbox environments (e.g., mcp__flow-nexus__sandbox_execute). This is a core feature of the platform for development and testing purposes.- [DYNAMIC_EXECUTION]: The skill allows for the creation of sandboxes with various templates (Node.js, Python, React) and the dynamic installation of packages at runtime via the mcp__flow-nexus__sandbox_create and mcp__flow-nexus__sandbox_configure tools.- [INDIRECT_PROMPT_INJECTION]: Several tools ingest external or user-provided data that could potentially influence agent behavior if not properly handled by the platform's backend.
  • Ingestion points: Tools like mcp__flow-nexus__seraphina_chat, mcp__flow-nexus__sandbox_execute, and mcp__flow-nexus__challenge_submit accept string inputs representing messages, source code, or solutions.
  • Boundary markers: Not explicitly defined within the provided tool usage instructions.
  • Capability inventory: Includes sandbox management, code execution, storage operations, and AI assistant orchestration.
  • Sanitization: Relies on the security controls of the Flow Nexus platform infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — flow-nexus-platform