skills/vm0-ai/vm0-skills/moss/Gen Agent Trust Hub

moss

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection by processing and retrieving user-provided documents.\n
  • Ingestion points: Content is ingested through the index document endpoint as described in the API usage examples.\n
  • Boundary markers: The skill guidelines do not include specific instructions or delimiters to help the agent distinguish between retrieved search results and authoritative system instructions.\n
  • Capability inventory: The skill utilizes curl for making network requests and writes temporary files to /tmp/.\n
  • Sanitization: There are no instructions for sanitizing, validating, or escaping external content before it is indexed or after it is retrieved.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 01:52 AM
Security Audit — agent-trust-hub — moss