mo-tag
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for simple data retrieval using a local command-line interface. No evidence of malicious behavior, obfuscation, or data exfiltration was found.
- [COMMAND_EXECUTION]: The skill specifies the use of the
moclibinary to executetag minecommands. This is the intended functionality of the skill and does not appear to involve arbitrary command injection or privilege escalation. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of tag names from the CLI output. 1. Ingestion points: Output of
mocli tag minein SKILL.md. 2. Boundary markers: References shared rules inmo-shared/SKILL.mdand explicitly requires user confirmation before selection. 3. Capability inventory: Execution ofmoclibinary. 4. Sanitization: Relies on user review for confirmation. This represents a low-risk surface managed by standard instructions.
Audit Metadata