moda-api

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a technical reference for the Moda REST API and does not contain any executable malicious payloads or suspicious instructions.
  • [DATA_EXPOSURE]: Documentation explicitly advises against hardcoding credentials, recommending the use of environment variables and secret managers (Vault, AWS Secrets Manager, etc.) to handle the moda_live_ API keys.
  • [NETWORK_OPERATIONS]: All described network operations target the official Moda API infrastructure at api.moda.app or well-known cloud services (AWS S3, Google Cloud Storage) as part of legitimate export workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents endpoints that ingest user-provided prompts and documents. While this represents a potential attack surface for the Moda service, the skill provides standard integration instructions and correctly notes that safety and validation are handled server-side.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 02:57 AM
Security Audit — agent-trust-hub — moda-api