flow-nexus-platform
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents and provides access to tools designed for executing code within isolated sandbox environments (e.g.,
mcp__flow-nexus__sandbox_execute). This is a core feature of the platform for development and testing purposes.- [DYNAMIC_EXECUTION]: The skill allows for the creation of sandboxes with various templates (Node.js, Python, React) and the dynamic installation of packages at runtime via themcp__flow-nexus__sandbox_createandmcp__flow-nexus__sandbox_configuretools.- [INDIRECT_PROMPT_INJECTION]: Several tools ingest external or user-provided data that could potentially influence agent behavior if not properly handled by the platform's backend. - Ingestion points: Tools like
mcp__flow-nexus__seraphina_chat,mcp__flow-nexus__sandbox_execute, andmcp__flow-nexus__challenge_submitaccept string inputs representing messages, source code, or solutions. - Boundary markers: Not explicitly defined within the provided tool usage instructions.
- Capability inventory: Includes sandbox management, code execution, storage operations, and AI assistant orchestration.
- Sanitization: Relies on the security controls of the Flow Nexus platform infrastructure.
Audit Metadata