moda-mcp
Pass
Audited by Gen Agent Trust Hub on May 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill acts as an interface for the Moda AI design agent. Analysis of the instructions and tool definitions shows no malicious patterns, obfuscation, or unauthorized access attempts.\n- [EXTERNAL_DOWNLOADS]: The skill connects to an external MCP server at mcp.moda.app and includes an
upload_filetool that can fetch content from user-provided URLs. These interactions are documented, restricted to the vendor's infrastructure, and necessary for the design use case.\n- [DATA_EXFILTRATION]: Network operations are directed to the legitimate service domain (moda.app). No evidence of unauthorized data harvesting or access to sensitive local environment data (such as credentials or SSH keys) was found.\n- [PROMPT_INJECTION]: The instructions provide operational guidance and recipes for the agent's design tasks. There are no patterns found that attempt to bypass safety guardrails or override core system instructions.
Audit Metadata