moda-api
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a technical reference for the Moda REST API and does not contain any executable malicious payloads or suspicious instructions.
- [DATA_EXPOSURE]: Documentation explicitly advises against hardcoding credentials, recommending the use of environment variables and secret managers (Vault, AWS Secrets Manager, etc.) to handle the
moda_live_API keys. - [NETWORK_OPERATIONS]: All described network operations target the official Moda API infrastructure at
api.moda.appor well-known cloud services (AWS S3, Google Cloud Storage) as part of legitimate export workflows. - [INDIRECT_PROMPT_INJECTION]: The skill documents endpoints that ingest user-provided prompts and documents. While this represents a potential attack surface for the Moda service, the skill provides standard integration instructions and correctly notes that safety and validation are handled server-side.
Audit Metadata