Back to skill

Security audit

Claude Flow

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent multi-agent orchestration purpose, but its install and runtime guidance asks users or agents to run mutable external code and register an unpinned MCP server with broad local workflow access.

Review carefully before installing. Do not let an agent auto-run the one-line installer. Prefer a pinned, reviewed package or installer, avoid ruflo@latest for MCP startup, pass only required credentials, keep API keys out of shell history and plaintext config where possible, and understand how to remove the user-scoped MCP registration and clear vector memory.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:69
Finding

Mutable Remote Installation Script Is Piped Directly into Bash

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
guides/01-installation.md:64
Finding

Unpinned npm Package Is Repeatedly Downloaded and Executed as a User-Scoped MCP Server

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
troubleshooting.md:56
Finding

API Credential Guidance Exposes Secrets Through Terminal Output, Process Arguments, and Plaintext Files

Content
View full analysis
> .env ``` `guides/03-advanced-usage.md:7-11` ```bash # Configure multiple providers npx ruflo@latest config set provider anthropic --api-key $ANTHROPIC_API_KEY npx ruflo@latest config set provider openai --api-key $OPENAI_API_KEY npx ruflo@latest config set provider google --api-key $GOOGLE_API_KEY ``` `troubleshooting.md:56-67` ```bash # Check API Key echo $ANTHROPIC_API_KEY # Should display sk-ant-... # Permanently configure it in the shell profile echo 'export ANTHROPIC_API_KEY="sk-ant-your-key"' >> ~/.zshrc source ~/.zshrc # Or configure it in Claude-Flow npx ruflo@latest config set api-key $ANTHROPIC_API_KEY ``` ### Technical Analysis The troubleshooting instructions explicitly print the API key to standard output. This can expose the secret through terminal history capture, screen sharing, support recordings, CI logs, or other logging systems. Expanding API keys in command-line arguments can make them visible to local process inspection while the command is running and may cause them to appear in diagnostic output. Writing credentials to `.env` or `~/.zshrc` creates persistent plaintext copies without guidance about restrictive permissions, repository exclusions, backups, or secret rotation. The manual MCP configuration also places the key in a JSON configuration file. Although persistent credentials may be required for MCP operation, the Skill does not specify a protected secret store or minimum filesystem permissions. ### Attack Path 1. A user follows the documented setup or troubleshooting instructions. 2. The API key is printed to t ...[truncated 1132 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (96)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

curl -fsSL https://.../install.sh | bash fetches a remote script and immediately executes it without any verification, pinning, or review step. This is dangerous because compromise of the repository, CDN, network path, or referenced branch content can lead to arbitrary code execution on the host, and the skill explicitly recommends this as the preferred install method.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

bash
# 一键安装(推荐)
curl -fsSL https://cdn.jsdelivr.net/gh/ruvnet/ruflo@main/scripts/install.sh | bash

# 或通过 npx
npx ruflo@latest init --wizard

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The | bash chaining pattern turns remote content retrieval directly into shell execution, eliminating opportunities for inspection and making accidental or malicious code execution far more likely. In an AI-skill context, this is especially risky because an agent may follow the instruction automatically, effectively granting arbitrary shell execution to untrusted remote content.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

bash
# 一键安装(推荐)
curl -fsSL https://cdn.jsdelivr.net/gh/ruvnet/ruflo@main/scripts/install.sh | bash

# 或通过 npx
npx ruflo@latest init --wizard

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

curl -fsSL ... | bash -s -- --full downloads and immediately executes a remote script from a CDN-backed GitHub path, with no checksum, signature verification, or requirement to inspect the content first. Because the URL tracks @main, the executed code is mutable over time, so compromise of the repo, CDN path, or upstream account can lead to arbitrary code execution on user machines.

Content

Scanner excerpt · guides/01-installation.md (reported line 17)May include surrounding context.

bash
# 完整安装(MCP + 诊断工具)
curl -fsSL https://cdn.jsdelivr.net/gh/ruvnet/ruflo@main/scripts/install.sh | bash -s -- --full

# 或仅基础安装
curl -fsSL https://cdn.jsdelivr.net/gh/ruvnet/ruflo@main/scripts/install.sh | bash

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The base install command repeats the same unsafe pattern of executing a remote script directly from a mutable @main URL. Recommending this in installation docs materially increases likelihood of exploitation because users are primed to trust and run the command exactly as written.

Content

Scanner excerpt · guides/01-installation.md (reported line 20)May include surrounding context.

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The | bash pipeline is a direct command-chaining pattern that removes any pause for inspection between fetch and execution. In this context, the documentation explicitly encourages running a fetched script immediately, which amplifies the risk of malicious content delivery or man-in-the-middle/upstream compromise resulting in instant code execution.

Content

Scanner excerpt · guides/01-installation.md (reported line 20)May include surrounding context.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The instruction to append ANTHROPIC_API_KEY to a .env file promotes plaintext local secret storage without discussing permissions, gitignore, or leakage paths. In developer environments, .env files are frequently copied, backed up, or accidentally committed, which can expose the API key.

Content

Scanner excerpt · guides/01-installation.md (reported line 56)May include surrounding context.

bash
export ANTHROPIC_API_KEY="sk-ant-..."

# 或写入 .env 文件
echo 'ANTHROPIC_API_KEY=sk-ant-...' >> .env

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

This finding is a duplicate manifestation of the same .env secret-handling issue in the adjacent line and remains a real risk because the guide normalizes plaintext credential persistence. The skill context makes it more concerning because the key is for a live AI service and may grant billable API access and data exposure.

Content

Scanner excerpt · guides/01-installation.md (reported line 57)May include surrounding context.

export ANTHROPIC_API_KEY="sk-ant-..."

或写入 .env 文件

echo 'ANTHROPIC_API_KEY=sk-ant-...' >> .env

text

---

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · guides/01-installation.md (reported line 73)May include surrounding context.

解决方案:

  • 必须重启 Claude Code — MCP 不热加载
  • 验证 MCP 已注册:claude mcp list
  • 手动检查配置:cat ~/.claude/settings.json | grep claude-flow
bash
# 重新添加 MCP(如果 list 中没有)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · troubleshooting.md (reported line 38)May include surrounding context.

解决方案:

  • 必须重启 Claude Code — MCP 不热加载
  • 验证 MCP 已注册:claude mcp list
  • 手动检查配置:cat ~/.claude/settings.json | grep claude-flow
bash
# 重新添加 MCP(如果 list 中没有)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · troubleshooting.md (reported line 187)May include surrounding context.

解决方案:

  • 必须重启 Claude Code — MCP 不热加载
  • 验证 MCP 已注册:claude mcp list
  • 手动检查配置:cat ~/.claude/settings.json | grep claude-flow
bash
# 重新添加 MCP(如果 list 中没有)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · troubleshooting.md (reported line 38)May include surrounding context.

解决方案:

  • 必须重启 Claude Code — MCP 不热加载
  • 验证 MCP 已注册:claude mcp list
  • 手动检查配置:cat ~/.claude/settings.json | grep claude-flow
bash
# 重新添加 MCP(如果 list 中没有)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill instructs users/agents to run npx ruflo@latest init --wizard, which executes a package resolved at runtime using the moving latest tag rather than a fixed version. If the package is compromised, typosquatted, or a bad release is published, an agent could execute attacker-controlled code during setup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill advertises automatic reuse/storage of successful patterns in persistent vector memory but does not warn users that task-derived data may be retained. In this context, users may provide code, secrets, internal architecture, or sensitive prompts, and silent persistence can create confidentiality and compliance risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown recommends a one-line install path that modifies the system but does not warn that it downloads and executes code, potentially alters configuration, and should only be used after review. In an agent skill context, omission of such warnings increases the chance that an autonomous assistant or user treats the command as routine and executes it without understanding the trust implications.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

npx ruflo@latest mcp start launches code from an unpinned npm package using the mutable latest tag. In this skill's context, that is more dangerous because it starts an MCP server inside the agent tooling environment, potentially giving compromised code broad access to workflows, files, and downstream tools.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

npx ruflo@latest agent list still requires fetching and executing package code from a non-pinned npm release. Even seemingly read-only commands can run arbitrary lifecycle or CLI code, so a compromised release could execute malicious actions on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

npx ruflo@latest swarm start ... executes a mutable package version and then starts a multi-agent orchestration workflow. Because this command may spawn broader automation and tool use, compromise of the fetched package could cascade into larger system-level or data-access impact than a simple local utility.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide recommends a one-line remote install script piped directly to bash and labels it as something AI can auto-execute, but provides no warning to inspect the script, pin to an immutable revision, or verify integrity. This is dangerous because it encourages immediate execution of externally hosted code with shell privileges, magnified by automation and likely reduced user scrutiny.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The documentation instructs users to run npx ruflo@latest, which fetches and executes the latest package version at install/runtime rather than a reviewed, immutable version. This creates a supply-chain risk: if the package is compromised or a breaking/malicious release is published, users and the MCP server will execute untrusted code automatically.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Using npx ruflo@latest init causes users to execute whatever code is currently published as the latest version, without any version pinning or review gate. In the context of an install guide for an orchestration tool with MCP integration, that means arbitrary newly-published package code may gain local execution on developer machines.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The API key instructions tell users to export a secret inline and append it to .env without warning about shell history, plaintext storage, file permissions, or accidental commit risk. This can lead to credential leakage through terminal history, world-readable files, backups, or source control.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The MCP auto-configuration command uses npx ruflo@latest mcp start, meaning the MCP server process will be sourced from the latest npm package each time the setup is followed. Because MCP servers run code locally and can interact with agent workflows, unpinned execution increases the blast radius of a package compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manual MCP configuration embeds ANTHROPIC_API_KEY in a plaintext settings file but does not warn users about local secret exposure, backups, sync services, or file-permission concerns. Storing API keys in static config files increases the chance of credential theft from the workstation or accidental disclosure.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
guides/03-advanced-usage.md:45