moai-lang-r
Pass
Audited by Gen Agent Trust Hub on Mar 2, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: No evidence of malicious code, obfuscation, or hardcoded secrets was found. The skill serves primarily as documentation and configuration metadata for R development standards.
- [NO_CODE]: The skill does not include any scripts or executable files; it consists entirely of markdown files and YAML configuration.
- [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it is designed to ingest untrusted project data using tools with high capabilities.
- Ingestion points: Language-specific source directories, configuration files, and test suites mentioned in SKILL.md.
- Boundary markers: None present; the skill does not define specific delimiters for separating data from instructions.
- Capability inventory: The skill uses Read (read_file), Bash (terminal), WebSearch, and WebFetch.
- Sanitization: No input validation or sanitization mechanisms are defined.
Audit Metadata