moda-chart
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were identified in the skill instructions or referenced materials.\n- [COMMAND_EXECUTION]: The skill utilizes the 'moda' CLI tool to manage canvas state, create design elements, and generate media. These commands are executed via a bash tool and are strictly limited to the platform's functional scope.\n- [DYNAMIC_EXECUTION]: The skill implements a sandboxed JavaScript environment for canvas mutations. The sandbox API is restricted to prevent unauthorized actions, such as resource removal or external network requests, and it enforces execution time limits to prevent denial-of-service.\n- [EXTERNAL_DOWNLOADS]: The skill supports fetching branding tokens and logo assets from external URLs. This functionality is handled by specialized vendor tools that process the data within the platform's secure environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external data formats like CSV and tables for visualization. It proactively mitigates injection risks by instructing the agent to treat canvas text as data rather than instructions.
Audit Metadata