moldea
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements strict path validation in
scripts/repository-files.mjsthrough theisPathWithinfunction, ensuring that all file read and write operations are restricted to the repository root to prevent directory traversal attacks. - [SAFE]: A custom launcher in
scripts/moldea-cli.mjsprovides a secure interface for executing the moldea CLI. It restricts execution to a specific set of commands (scope,validate,inspect,content,composition), prevents shell injection by usingchild_process.spawnwithout a shell, and enforces strict output byte limits to mitigate resource exhaustion. - [SAFE]: The
scripts/managed-readme.mjsutility ensures safe modification of the repository's README.md by using atomic writes and strict marker-based boundaries (<!-- moldea:start -->and<!-- moldea:end -->), protecting content outside the managed region. - [SAFE]: Security-focused instructions in
references/tooling-installation.mdandreferences/local-tooling.mdguide the agent to verify executable provenance and maintain host execution controls, such as disabling lifecycle scripts during dependency installation.
Audit Metadata