moonpay-missions

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Uses the mp CLI for financial operations, including wallet creation (mp wallet create), message signing, and token swaps.
  • [COMMAND_EXECUTION]: Mission 9 uses mp skill install to copy instruction files to the agent's local directory (~/.claude/skills/), which persists capabilities across sessions.
  • [PROMPT_INJECTION]: Provides an indirect prompt injection surface by ingesting data from external token and market lookups. Ingestion points: mp token search and mp prediction-market. Boundary markers: None. Capability inventory: mp token swap and mp skill install. Sanitization: None.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 10:25 PM