moai-foundation-claude
Fail
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: CRITICALNO_CODE
Full Analysis
- [SAFE]: The skill is entirely composed of documentation and template files (Markdown) providing instructions for Claude Code authoring. It does not contain any scripts, binary executables, or automated triggers that execute code on load.
- [IAM]: The skill includes extensive documentation on Identity and Access Management (IAM), tool-specific permission rules, and security boundaries. It explicitly recommends the principle of least privilege and provides checklists for validating permissions.
- [COMMAND_EXECUTION]: The documentation provides examples for custom slash commands and hooks. These are presented as educational templates and include clear security warnings regarding the execution of arbitrary shell commands and the use of permissive modes like
dontAsk. - [EXTERNAL_DOWNLOADS]: The skill references well-known services and trusted organizations (such as GitHub, NPM, and Upstash) for documentation and tool integration. These references are informative and align with standard developer workflows.
- [REMOTE_CODE_EXECUTION]: While the skill describes automation capabilities, it provides specific defensive patterns, such as input sanitization and command validation hooks, to prevent remote code execution vulnerabilities in user-developed tools.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata