Oathe Security Badge

Is taylorbanks/moshpit safe?

Yes. taylorbanks/moshpit is safe to install. Oathe's behavioral security audit gave the moshpit skill by taylorbanks a trust score of 94/100 with 5 findings, none critical or high. Report updated

https://github.com/taylorbanks/moshpit

94
SAFE

Is taylorbanks/moshpit safe to install?

taylorbanks/moshpit is a legitimate open-source Go terminal UI for managing SSH and Mosh server connections, forked from LazySSH. It contains no SKILL.md and is not designed as an LLM agent skill — there is no prompt injection surface. The clone was clean, canary files were untouched, and the only network activity was the GitHub clone itself. The application's legitimate purpose involves reading ~/.ssh/config and spawning system SSH processes, which is fully disclosed in the README.

What security issues were found in taylorbanks/moshpit?

Category Scores

Prompt Injection 100/100 · 30%
Data Exfiltration 90/100 · 25%
Code Execution 90/100 · 20%
Clone Behavior 93/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 88/100 · 5%

Findings (5)

INFO No SKILL.md — not an agent skill 0 ▶

The repository contains no SKILL.md file and is not structured as an LLM agent skill. There is no agent instruction surface, no prompt injection vector, and no mechanism by which this repository could influence agent behavior when loaded into a system prompt.

LOW Application legitimately reads ~/.ssh/config and detects SSH keys -10 ▶

The Go source in internal/adapters/ui/ssh_key_picker.go and internal/adapters/data/ssh_config_file/ reads the user's SSH config and enumerates private key files for autocomplete. This is the application's core disclosed purpose, not malicious behavior. However, any tool with this access should be reviewed before granting agent control.

LOW Binary spawns ssh and mosh system processes on demand -10 ▶

When run, the application executes the system ssh and mosh binaries to connect to servers. This is its stated and legitimate purpose. An AI agent with tool access to this binary could initiate SSH connections to any host in the config.

INFO Clean clone — only GitHub network activity 0 ▶

The only external TCP connection during the audit window was to 140.82.121.4:443 (GitHub) for the HTTPS git clone. No DNS lookups to unexpected domains, no C2 beacons, no data uploads. The pre-existing connection to 185.125.188.54:443 (Canonical/Ubuntu) predates the clone and is unrelated.

INFO Canary file reads attributable to monitoring infrastructure 0 ▶

Inotify and auditd both record read-only access to canary files (.env, id_rsa, .aws/credentials, etc.) at two points: before the clone started (baseline capture) and after the scan completed (integrity verification). All accesses are CLOSE_NOWRITE — no data was written or transmitted. The monitoring system confirms all canary files intact.

Should I install taylorbanks/moshpit?

Oathe's verdict for taylorbanks/moshpit is SAFE with a trust score of 94/100. Recommendation: Install.