moodle-external-api-development

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill provides an example curl command for authentication that includes a password in the request body via the '-d' flag. This practice can leak credentials through shell history or process monitoring tools on the system. (File: SKILL.md)
  • [COMMAND_EXECUTION]: The skill includes PHP implementation examples that recommend creating directories with world-writable permissions using 'mkdir($logdir, 0777, true)'. Setting permissions to 0777 is a security risk as it allows any user on the system to read, write, or delete files in that directory. (File: SKILL.md)
  • [DATA_EXFILTRATION]: The skill encourages logging sensitive system information, including full stack traces via '$e->getTraceAsString()' and the last executed database query via '$DB->get_last_sql()'. If the resulting log files are not properly restricted, this could lead to significant information disclosure regarding application architecture and database schema. (File: SKILL.md)
  • [PROMPT_INJECTION]: The skill documents how to build APIs that ingest untrusted data, creating a surface for indirect prompt injection attacks.
  • Ingestion points: External data enters the system through API parameters defined in the 'execute_parameters()' method in 'SKILL.md'.
  • Boundary markers: Absent; there are no instructions to use delimiters or ignore instructions within the processed data.
  • Capability inventory: The skill uses database operations ($DB), file system writes (file_put_contents), and course management tools (add_course_module) in 'SKILL.md'.
  • Sanitization: The skill recommends the use of 'validate_parameters()' and Moodle's 'PARAM_*' constants for data validation and typing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — moodle-external-api-development