skills/modal-labs/modal-client/modal/Gen Agent Trust Hub

modal

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides detailed instructions on using the modal CLI tool to interact with the platform. This includes commands for resource management, app observation, and a specific modal skills update command intended to update the skill's own instructions from the vendor's infrastructure.
  • [EXTERNAL_DOWNLOADS]: The instructions direct the agent to fetch documentation from vendor-controlled URLs, specifically https://modal.com/llms.txt and https://modal.com/llms-full.txt, to stay up-to-date with API changes.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest data from external URLs which creates a surface for indirect prompt injection.
  • Ingestion points: Documentation URLs https://modal.com/llms.txt and https://modal.com/llms-full.txt mentioned in SKILL.md.
  • Boundary markers: None identified; the agent is encouraged to read these files directly into context.
  • Capability inventory: The agent has the capability to execute shell commands via the modal CLI.
  • Sanitization: No specific sanitization or validation of the fetched documentation content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 10:18 PM
Security Audit — agent-trust-hub — modal