moshi-best-practices

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONPERSISTENCEPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill executes remote scripts by piping curl output from herdr.dev and getmoshi.app directly to the shell. It also leverages npx to install skills from third-party repositories like ogulcancelik/herdr.
  • [PERSISTENCE]: The skill configures systemd user units and brew services to ensure that the moshi-hook daemon remains active across system restarts.
  • [PRIVILEGE_ESCALATION]: The skill includes instructions to use the security unlock-keychain command, which allows access to sensitive credentials stored in the macOS login keychain.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection by interpolating untrusted user tokens and repository paths into sensitive system commands. 1. Ingestion points: Token and repository arguments in SKILL.md. 2. Boundary markers: No delimiters or protective warnings are implemented. 3. Capability inventory: Includes piped shell execution, persistence mechanisms, and keychain access. 4. Sanitization: No sanitization or validation of external input is performed.
Recommendations
  • HIGH: Downloads and executes remote code from: https://getmoshi.app/install.sh, https://herdr.dev/install.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 02:01 AM