oc-status

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface. * Ingestion points: Reads data from _log.yaml, matter.md, and history.md (SKILL.md). * Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the ingested text. * Capability inventory: Limited to reading files and writing markdown drafts to the local filesystem; no network, shell, or code execution capabilities are present (SKILL.md). * Sanitization: No sanitization or validation of the case content is performed before interpolating it into the email template.- [DATA_EXFILTRATION]: No network-enabled tools (like curl or wget) or data exfiltration patterns were detected. All operations are local.- [REMOTE_CODE_EXECUTION]: No remote dependencies or script downloads were found.- [COMMAND_EXECUTION]: The skill does not perform any direct shell command execution or subprocess spawning.- [CREDENTIALS_UNSAFE]: No hardcoded secrets or sensitive configuration files outside of the plugin's own working directory are accessed.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:07 AM
Security Audit — agent-trust-hub — oc-status