writing-motoko

Fail

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to consult https://docs.mops.one/ for troubleshooting unfamiliar errors. This domain has been flagged as a phishing risk by automated security scanners, which could potentially expose the agent to malicious content or social engineering instructions while resolving technical issues.
  • [COMMAND_EXECUTION]: The instructions authorize the agent to execute various shell commands through the mops toolchain, including mops add, mops update, mops sync, mops install, mops check, and mops build. This provides a significant surface for command execution within the development environment.
  • [REMOTE_CODE_EXECUTION]: The skill facilitates fetching and integrating remote code via the mops add <url> command, which allows pulling dependencies from arbitrary GitHub repositories or other external URLs without mandatory verification mechanisms.
  • [DYNAMIC_EXECUTION]: The agent is instructed to run mops build, which compiles Motoko source code into WebAssembly (Wasm). This process executes the compiler and generates executable artifacts from potentially unverified or externally sourced code.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting code from external packages and processing migration files.
  • Ingestion points: External package code fetched via mops add, project source files, and actor migration scripts (migrations/*.mo).
  • Boundary markers: The instructions lack specific delimiters or safety warnings to prevent the agent from following directives embedded within the third-party code it processes.
  • Capability inventory: The agent has capabilities to modify the file system and execute shell commands through the mops CLI for dependency management and compilation.
  • Sanitization: There are no documented mechanisms for sanitizing external inputs or validating the integrity of packages beyond basic lockfile maintenance.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Oct 2, 2026, 08:08 AM
Security Audit — agent-trust-hub — writing-motoko