morph-apply

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses uv run to execute a local Python script scripts/mcp/morph_apply.py. This script serves as the interface for applying file edits through the external API.
  • [DATA_EXFILTRATION]: The skill transmits portions of the user's code and editing instructions to the Morph Apply API for processing. This data transfer is fundamental to the tool's operation as a remote AI-powered code editor and targets the vendor's documented infrastructure.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes file content and user-provided instructions which are then sent to an external API. • Ingestion points: User-provided --instruction and --code_edit arguments in SKILL.md. • Boundary markers: No explicit delimiters or guardrails are specified in the instructions to separate code from potential embedded commands. • Capability inventory: File reading and shell command execution capabilities via allowed-tools. • Sanitization: The skill description does not document specific sanitization or validation steps for the input parameters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — morph-apply