Skills flow-nexus-platform
📦

flow-nexus-platform

Content revision r2 High Risk ⚙️ External commands🌐 Network access🔑 Env variables

Manage Flow Nexus Platform Operations

Flow Nexus workflows span many tools and operational domains. This skill provides one guide for accounts, sandboxes, deployments, billing, storage, and monitoring.

Supports: Claude Codex Code(CC)
⚠️ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "flow-nexus-platform" from https://skillstore.io/skills/ruvnet-flow-nexus-platform.md and its manifest at https://skillstore.io/api/skills/ruvnet-flow-nexus-platform/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "flow-nexus-platform". Check my platform status without changing anything.

Expected outcome:

  • Authentication: active.
  • Credits: 240 remaining.
  • Sandboxes: two running and one stopped.
  • System health: operational.

Using "flow-nexus-platform". Prepare a Node.js sandbox with Express and dotenv, but ask before creation.

Expected outcome:

Prepared a Node.js sandbox plan with two packages, no secrets, a one-hour timeout, and confirmation required before creation.

Using "flow-nexus-platform". Compare backend templates and prepare a deployment plan for inventory-api.

Expected outcome:

Compared suitable backend templates and prepared a staged deployment plan with testing, secret references, cost review, monitoring, and rollback.

Security Audit

High Risk
v8 • 7/23/2026 Open versioned report

Most static alerts are false positives caused by Markdown fences, JavaScript template strings, and placeholder credentials. Confirmed risks include outbound network access, repository cloning, remote command execution, secret transmission, paid actions, delegated tools, and destructive platform mutations. No prompt injection, obfuscation, or embedded live credential was found.

1
Files scanned
1,155
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (6)

High
Remote Code and Command Execution
The skill instructs agents to install packages and execute caller-supplied code and shell commands in remote sandboxes. Malicious inputs or dependencies can execute untrusted code and consume resources.
The cited examples directly provide run_commands, startup_script, package installation, and sandbox_execute inputs.
High
Sensitive Credentials Sent to Hosted Operations
Examples pass API keys, database URLs, application secrets, and an Anthropic key into Flow Nexus operations. Real replacements would disclose credentials to a community-operated external service.
The documented MCP parameters explicitly accept API keys, database connection strings, secrets, and an Anthropic key.
High
Financial Actions and Recurring Charges
The skill can create payment links and enable automatic credit purchases. Agent execution without explicit approval could cause unintended charges.
The examples directly configure a payment amount and enable auto-refill with a recurring purchase threshold.
High
Delegated Assistant Can Invoke Tools
The Seraphina example enables tools that can create swarms and deploy code. Delegation can expand impact beyond the user's immediate request.
The example sets enable_tools to true and states that the assistant can create swarms and deploy code.
High
Destructive and Public Platform Mutations
The skill documents sandbox deletion, storage deletion, application publication, application updates, and template deployment. Incorrect targets can destroy data or expose unreviewed source code.
The cited MCP calls directly delete resources, publish source code, update applications, and deploy templates.
High
Caller-Supplied Entitlement and Credit Mutations
Examples accept caller-supplied user identifiers, tiers, credit amounts, and reasons for entitlement changes. Weak server authorization could permit balance or tier abuse.
The parameters support direct account and credit mutations, but server-side authorization behavior is not present in the audited file.
Capability review items (4)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Ruby/shell backtick execution
`
The backtick closes a startup script containing apt-get, git clone, and npm install commands sent to a remote sandbox. Following the example executes commands and installs third-party code.
Medium
Hardcoded URL
git clone https://github.com/user/repo
The startup script clones a remote repository and then runs npm install. A mutable or untrusted repository can introduce malicious package code and install hooks.
Low
Fetch API call
const result = await fetch('https://api.example.com/data');
The example passes a fetch call to sandbox_execute, causing a real outbound request when followed. The endpoint is a placeholder, but remote network access is explicit.
Low
Hardcoded URL
const result = await fetch('https://api.example.com/data');
The example passes a fetch call to sandbox_execute, causing a real outbound request when followed. The endpoint is a placeholder, but remote network access is explicit.
Audited by: codex View Audit History →
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/ruvnet-flow-nexus-platform/audits/8?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/ruvnet-flow-nexus-platform/security.svg)](https://skillstore.io/skills/ruvnet-flow-nexus-platform?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/ruvnet-flow-nexus-platform?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/ruvnet-flow-nexus-platform/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/ruvnet-flow-nexus-platform.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA · BibTeX · CFF)

APA citation

ruvnet. (2026). flow-nexus-platform security audit report (audit version 8) [Author version unspecified]. Skillstore. https://skillstore.io/skills/ruvnet-flow-nexus-platform/audits/8

BibTeX citation

@techreport{ruvnet-ruvnet-flow-nexus-platform-2026, author = {ruvnet}, title = {flow-nexus-platform security audit report (audit version 8)}, institution = {Skillstore}, year = {2026}, number = {8}, url = {https://skillstore.io/skills/ruvnet-flow-nexus-platform/audits/8}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "flow-nexus-platform security audit report (audit version 8)" version: "unspecified" type: report authors: - name: "ruvnet" date-released: "2026-07-23" url: "https://skillstore.io/skills/ruvnet-flow-nexus-platform/audits/8" identifiers: - type: other value: "skillstore:ruvnet-flow-nexus-platform:audit:8" description: "Skillstore immutable audit report identifier"

Compare variants

2 installable variants

Each author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.

Why this variant is first

Higher Skillstore usage
ruvnet Recommended Current

ruvnet-flow-nexus-platform

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 10
Updated

2026-08-21

dnyoussef-flow-nexus-platform

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 6
Updated

2026-08-21

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
70
Community
70
Spec Compliance

What You Can Build

Prototype in remote sandboxes

Create an isolated Node.js or Python environment, install dependencies, run code, and inspect logs before deployment.

Operate hosted applications

Search templates, deploy services, publish updates, monitor execution, and manage stored artifacts from one workflow.

Track usage and learning

Review balances, transactions, challenges, achievements, and leaderboards while controlling paid credit settings.

Try These Prompts

Check account and platform status
Check my Flow Nexus authentication status, credit balance, active sandboxes, and system health. Summarize results without making changes.
Create a development sandbox
Create a Node.js sandbox named [name] with [packages]. Do not include secrets. Show the planned configuration before execution.
Deploy a reviewed application
Find a suitable [category] template, compare options, and prepare deployment [name]. Ask before deploying or adding paid resources.
Plan a controlled production workflow
Design a staged Flow Nexus workflow for [application]. Include sandbox tests, pinned dependencies, secret handling, deployment approval, monitoring, rollback, and cost controls.

Best Practices

  • Review and confirm every payment, auto-refill, publication, deployment, deletion, and account change before execution.
  • Use scoped secrets through approved secret storage, and never place live credentials in prompts, examples, logs, or source code.
  • Pin trusted packages and repository revisions, test in isolated sandboxes, monitor costs, and remove unused resources promptly.

Avoid

  • Do not enable delegated tools or arbitrary shell commands without an explicit allowlist and user approval.
  • Do not upload sensitive files to public buckets or return public URLs for confidential data.
  • Do not assume example prices, limits, tiers, endpoints, or platform behavior remain current.

Frequently Asked Questions

What setup is required?
You need a configured Flow Nexus MCP server, an authenticated account, and permissions for the requested operations.
Can this skill run code?
Yes. It can request code execution in remote sandboxes, so review all code, commands, packages, and resource limits first.
Can this skill create charges?
Yes. It can create payment links and configure auto-refill. Paid actions should require explicit confirmation.
How should secrets be handled?
Use scoped secrets from approved secret storage. Never place live credentials in prompts, examples, logs, or published application source.
Can it publish or delete resources?
Yes. It can publish applications and delete sandboxes or files. Confirm ownership, target identifiers, visibility, and recovery options.
Does it verify third-party code?
No. Review and pin repositories, packages, templates, and application source before installation, execution, publication, or deployment.

Developer Details

Author

ruvnet

License

MIT

Skillstore revision

r2

Version notice

The author did not declare a version.

Ref

ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006

Maintenance freshness

7/25/2026

Usage

7 downloads · 187 views

File structure

📄 SKILL.md

More from ruvnet

View all
View all