moodle-external-api-development
Fail
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill's sample code for logging includes
mkdir($logdir, 0777, true), which assigns full read, write, and execute permissions to all users on the system for the log directory. This bypasses standard access controls and could be exploited to tamper with logs or access sensitive data stored in the application's data root. - [INDIRECT_PROMPT_INJECTION]: The skill defines a framework for building APIs that ingest untrusted external data, creating an attack surface for indirect prompt injection.
- Ingestion points: External parameters defined in
execute_parameters()withinSKILL.md. - Boundary markers: The skill demonstrates the use of
validate_parameters()andvalidate_context()to enforce boundaries. - Capability inventory: The code exhibits capabilities for file system writes via
file_put_contentsand various database operations using Moodle's$DBobject. - Sanitization: The skill uses Moodle's built-in parameter types (e.g.,
PARAM_INT,PARAM_TEXT) to sanitize input data.
Recommendations
- AI detected serious security threats
Audit Metadata