moatmri

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external inputs such as industry types and target company names to generate strategic analysis, which creates a surface for indirect prompt injection.
  • Ingestion points: Industry, Entity type, and Target name fields (SKILL.md).
  • Boundary markers: Absent; user-provided data is interpolated directly into the disruption storyboard and analysis vectors.
  • Capability inventory: The skill defines natural language analysis and narrative generation; it does not explicitly invoke file system, network, or code execution tools.
  • Sanitization: None provided for user-supplied strings.
  • [EXTERNAL_DOWNLOADS]: The skill references external resources including a GitHub repository (github.com/thebrierfox/moatmri-skill) and a license server for 'Bring Your Own Key' (BYOK) functionality (ace-license-server-production.up.railway.app). These links are for optional user interaction and are not automatically accessed or executed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 07:15 PM
Security Audit — agent-trust-hub — moatmri