Back to skill

Security audit

moa-engine

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate orchestration skill, but it needs Review because it can automatically save learning data and change future agent behavior without clear user controls.

Install only if you want a multi-agent analysis workflow that may keep and reuse performance signals across runs. Before using it on sensitive privacy, financial, medical, legal, compliance, or security work, confirm where audit outputs and signal files will be stored, whether profile updates can be disabled, and whether any prompt or harness evolution requires your approval.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding
The skill advertises and instructs use of local CLI tooling that reads and writes files, but no explicit permission model or user-facing disclosure is declared. In an agent environment, hidden file access expands the trust boundary and can lead to unintended reads of local data or persistent modification of profile/state files without informed consent.

Tp4

High
Category
MCP Tool Poisoning
Confidence
83% confidence
Finding
The stated purpose frames the skill as a coordination/orchestration aid, but the content also includes operational capabilities such as persistent registry management, classifier CLIs, red-team prompt generation, and fitness/prompt evolution workflows. That mismatch can mislead users and supervising agents about the real side effects and execution surface, increasing the chance that higher-risk functions are invoked without appropriate review.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill states that high-risk tasks automatically enable audit logging and that execution signals are automatically used to update persistent expert profiles, yet it does not provide clear user warning, consent, retention limits, or data minimization guidance. For sensitive domains like privacy, finance, medical, security, or compliance, silent logging and stateful learning can capture sensitive task content and create durable records beyond user expectations.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation condition is described in very broad terms such as 'high-quality output', 'multi-angle analysis', and 'deep architecture review', which can cause the skill to be invoked for an overly wide range of tasks. In an orchestration skill that amplifies internal reasoning structure and may trigger multiple planning/red-team phases, ambiguous activation increases the chance of inappropriate routing, unnecessary exposure of sensitive user prompts to extra internal components, and policy-bypassing through overuse of a powerful workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.