mops-cli
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for executing various
mopsCLI commands such asmops install,mops build,mops test, andmops toolchain. These are standard project management operations and are executed in the local user environment. - [INDIRECT_PROMPT_INJECTION]: The skill involves the agent reading project configuration files (
mops.toml,mops.lock) and Motoko source code (.mo). This establishes a surface for indirect prompt injection where content within these files could potentially influence agent behavior. However, this is inherent to the tool's primary purpose, and no instructions facilitate unsafe data interpolation. - [EXTERNAL_DOWNLOADS]: The skill references the
mops toolchaincommand, which is used to download and pin binaries like the Motoko compiler (moc),lintoko, andpocket-ic. These downloads are essential for Motoko development and originate from expected ecosystem sources.
Audit Metadata