mastra
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process documentation from external sources, which represents an indirect prompt injection surface. The ingestion points include local documentation files within
node_modules/@mastra/*/dist/docs/and remote content fetched from the officialmastra.aiwebsite. While instructions direct the agent to verify memory against these docs, there is no explicit sanitization for the retrieved content. The capability inventory includesls,cat,grep, andcurlfor retrieval, plus themastra apiCLI for resource interaction.\n- [COMMAND_EXECUTION]: The skill documents numerous shell commands for project setup (npm create mastra), dependency management, and system operations (ls,docker run). It also provides detailed instructions for themastra apiCLI, which executes commands to interact with agent and workflow resources on local and remote servers.\n- [EXTERNAL_DOWNLOADS]: The skill fetches documentation and interacts with platform APIs atmastra.ai,observability.mastra.ai, andoutput.signals.mastra.ai. These are recognized as legitimate vendor resources for the Mastra framework.
Audit Metadata