Cloud-based AI swarm deployment and event-driven workflow automation with Flow Nexus platform
71
57%
Does it follow best practices?
Impact
100%
1.88xAverage score across 3 eval scenarios
Low
Low-risk findings worth noting
Fix and improve this skill with Tessl
tessl review fix ./.agents/skills/flow-nexus-swarm/SKILL.mdLow
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
Third-party content exposure detected (high risk: 0.80). The SKILL.md explicitly spawns "researcher" agents with a "web_search" capability and includes a "Research & Analysis" pattern and GitHub-triggered workflows that describe distributed information gathering, indicating the agents will fetch and interpret public third-party web content as part of their workflow and thus could be influenced by external (untrusted) sources.
26c35b5
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.