moodle-external-api-development

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The logging example provided in SKILL.md (Step 6) uses mkdir($logdir, 0777, true), which creates a world-writable directory. This violates the principle of least privilege and could allow unauthorized local users to read, modify, or delete log files.
  • [DATA_EXFILTRATION]: The error handling logic in SKILL.md (Step 6) logs sensitive system information, including full stack traces ($e->getTraceAsString()) and the last executed database query ($DB->get_last_sql()), to the filesystem. Exposure of such internal details can assist an attacker in mapping the system architecture and database schema.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of APIs that ingest and process external data, establishing a potential injection vulnerability surface.
  • Ingestion points: API parameters defined in execute_parameters() and received by the execute() method in the provided PHP class examples.
  • Boundary markers: The guide instructs developers to use Moodle's validate_parameters() method to verify input against expected schemas.
  • Capability inventory: The implemented APIs have access to database operations through the $DB global and filesystem access via mkdir and file_put_contents in the logging example.
  • Sanitization: The instructions recommend using Moodle's PARAM_* constants (e.g., PARAM_INT, PARAM_TEXT) to clean and validate input values.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — moodle-external-api-development