moodle-external-api-development

Fail

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill's sample code for logging includes mkdir($logdir, 0777, true), which assigns full read, write, and execute permissions to all users on the system for the log directory. This bypasses standard access controls and could be exploited to tamper with logs or access sensitive data stored in the application's data root.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a framework for building APIs that ingest untrusted external data, creating an attack surface for indirect prompt injection.
  • Ingestion points: External parameters defined in execute_parameters() within SKILL.md.
  • Boundary markers: The skill demonstrates the use of validate_parameters() and validate_context() to enforce boundaries.
  • Capability inventory: The code exhibits capabilities for file system writes via file_put_contents and various database operations using Moodle's $DB object.
  • Sanitization: The skill uses Moodle's built-in parameter types (e.g., PARAM_INT, PARAM_TEXT) to sanitize input data.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 28, 2026, 05:45 AM
Security Audit — agent-trust-hub — moodle-external-api-development