moai-lang-javascript

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection] (LOW): Evidence Chain: 1. Ingestion points: Reads .js, .mjs, .cjs, and package.json files. 2. Boundary markers: Absent. 3. Capability inventory: Provides execution capabilities for node, npm, yarn, pnpm, bun, deno, jest, and vitest via Bash tool. 4. Sanitization: Absent.
  • [Remote Code Execution] (SAFE): Mentions package installation (npm, yarn) but does not contain patterns for piped remote execution (e.g., curl|bash).
  • [Privilege Escalation] (SAFE): No usage of sudo or unauthorized system permission modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:19 PM