skills/mowenxd/cli/mo-tag/Gen Agent Trust Hub

mo-tag

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for simple data retrieval using a local command-line interface. No evidence of malicious behavior, obfuscation, or data exfiltration was found.
  • [COMMAND_EXECUTION]: The skill specifies the use of the mocli binary to execute tag mine commands. This is the intended functionality of the skill and does not appear to involve arbitrary command injection or privilege escalation.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of tag names from the CLI output. 1. Ingestion points: Output of mocli tag mine in SKILL.md. 2. Boundary markers: References shared rules in mo-shared/SKILL.md and explicitly requires user confirmation before selection. 3. Capability inventory: Execution of mocli binary. 4. Sanitization: Relies on user review for confirmation. This represents a low-risk surface managed by standard instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 11:46 AM
Security Audit — agent-trust-hub — mo-tag