moai-foundation-ears
Pass
Audited by Gen Agent Trust Hub on Mar 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection through external tool integration.
- Ingestion points: The skill logic in
SKILL.mddescribes fetching external documentation using themcp__context7__get-library-docstool. - Boundary markers: There are no explicit delimiters or instructions defined to isolate the external data from the agent's core instructions or to warn against embedded commands.
- Capability inventory: The skill is granted access to high-privilege tools including
Bash,Write, andWebFetch. - Sanitization: The skill does not implement any validation or sanitization of the content retrieved from the Context7 documentation library before processing it.
Audit Metadata