moonpay-missions
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Uses the
mpCLI for financial operations, including wallet creation (mp wallet create), message signing, and token swaps. - [COMMAND_EXECUTION]: Mission 9 uses
mp skill installto copy instruction files to the agent's local directory (~/.claude/skills/), which persists capabilities across sessions. - [PROMPT_INJECTION]: Provides an indirect prompt injection surface by ingesting data from external token and market lookups. Ingestion points:
mp token searchandmp prediction-market. Boundary markers: None. Capability inventory:mp token swapandmp skill install. Sanitization: None.
Audit Metadata