moai-cc-skill-factory

Pass

Audited by Gen Agent Trust Hub on Mar 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Comprehensive analysis of the skill's logic and scripts reveals no malicious intent or security vulnerabilities. The package is well-organized and follows documented safety standards for developer tools.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to run local automation scripts for project scaffolding and quality auditing. Scripts such as validate-skill.sh perform safe, local file operations to ensure development standards are met within the agent's workspace.
  • [EXTERNAL_DOWNLOADS]: Employs WebFetch and WebSearch tools to retrieve current technical documentation and best practices. It also utilizes specialized MCP tools to fetch data from well-known sources, such as Anthropic's public skill libraries, which are considered trusted references.
  • [PROMPT_INJECTION]: No evidence of prompt injection or instruction overrides was detected. The skill's instructions focus on structured AI orchestration, multi-model compatibility testing, and localized UX optimization for developers.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 2, 2026, 05:14 PM