skills/moldea-ai/skill/moldea/Gen Agent Trust Hub

moldea

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements strict path validation in scripts/repository-files.mjs through the isPathWithin function, ensuring that all file read and write operations are restricted to the repository root to prevent directory traversal attacks.
  • [SAFE]: A custom launcher in scripts/moldea-cli.mjs provides a secure interface for executing the moldea CLI. It restricts execution to a specific set of commands (scope, validate, inspect, content, composition), prevents shell injection by using child_process.spawn without a shell, and enforces strict output byte limits to mitigate resource exhaustion.
  • [SAFE]: The scripts/managed-readme.mjs utility ensures safe modification of the repository's README.md by using atomic writes and strict marker-based boundaries (<!-- moldea:start --> and <!-- moldea:end -->), protecting content outside the managed region.
  • [SAFE]: Security-focused instructions in references/tooling-installation.md and references/local-tooling.md guide the agent to verify executable provenance and maintain host execution controls, such as disabling lifecycle scripts during dependency installation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 06:22 PM
Security Audit — agent-trust-hub — moldea