moai-baas-auth0-ext
Pass
Audited by Gen Agent Trust Hub on Mar 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits vulnerability to indirect prompt injection attacks.
- Ingestion points: The skill utilizes
mcp__context7__get-library-docsto retrieve external documentation andWebFetchto access web content. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard potentially malicious instructions embedded within the external data sources.
- Capability inventory: The skill is granted
Bash,Write, andEdittools, which could be leveraged to perform unauthorized actions if the agent follows instructions found in fetched data. - Sanitization: No sanitization or validation logic is present to filter or escape content retrieved from remote sources before it is processed by the LLM.
Audit Metadata