writing-motoko
Fail
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs the agent to consult
https://docs.mops.one/for troubleshooting unfamiliar errors. This domain has been flagged as a phishing risk by automated security scanners, which could potentially expose the agent to malicious content or social engineering instructions while resolving technical issues. - [COMMAND_EXECUTION]: The instructions authorize the agent to execute various shell commands through the
mopstoolchain, includingmops add,mops update,mops sync,mops install,mops check, andmops build. This provides a significant surface for command execution within the development environment. - [REMOTE_CODE_EXECUTION]: The skill facilitates fetching and integrating remote code via the
mops add <url>command, which allows pulling dependencies from arbitrary GitHub repositories or other external URLs without mandatory verification mechanisms. - [DYNAMIC_EXECUTION]: The agent is instructed to run
mops build, which compiles Motoko source code into WebAssembly (Wasm). This process executes the compiler and generates executable artifacts from potentially unverified or externally sourced code. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting code from external packages and processing migration files.
- Ingestion points: External package code fetched via
mops add, project source files, and actor migration scripts (migrations/*.mo). - Boundary markers: The instructions lack specific delimiters or safety warnings to prevent the agent from following directives embedded within the third-party code it processes.
- Capability inventory: The agent has capabilities to modify the file system and execute shell commands through the
mopsCLI for dependency management and compilation. - Sanitization: There are no documented mechanisms for sanitizing external inputs or validating the integrity of packages beyond basic lockfile maintenance.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata