moshi-best-practices
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONPERSISTENCEPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill executes remote scripts by piping curl output from herdr.dev and getmoshi.app directly to the shell. It also leverages npx to install skills from third-party repositories like ogulcancelik/herdr.
- [PERSISTENCE]: The skill configures systemd user units and brew services to ensure that the moshi-hook daemon remains active across system restarts.
- [PRIVILEGE_ESCALATION]: The skill includes instructions to use the security unlock-keychain command, which allows access to sensitive credentials stored in the macOS login keychain.
- [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection by interpolating untrusted user tokens and repository paths into sensitive system commands. 1. Ingestion points: Token and repository arguments in SKILL.md. 2. Boundary markers: No delimiters or protective warnings are implemented. 3. Capability inventory: Includes piped shell execution, persistence mechanisms, and keychain access. 4. Sanitization: No sanitization or validation of external input is performed.
Recommendations
- HIGH: Downloads and executes remote code from: https://getmoshi.app/install.sh, https://herdr.dev/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata