oma-backend
Pass
Audited by Gen Agent Trust Hub on May 16, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: Analyzed instructions for safety filter bypasses or behavioral overrides; no such patterns found. All directives are aligned with intended backend development tasks.- [CREDENTIALS_UNSAFE]: Verified that templates and snippets do not contain hardcoded secrets; the skill mandates the use of environment variables for database URLs, API keys, and secrets.- [COMMAND_EXECUTION]: Shell commands defined in stack manifests are restricted to standard development tools (bun, cargo, pytest) used for code verification and linting.- [INDIRECT_PROMPT_INJECTION]: The skill processes codebase files which presents an inherent surface; this is mitigated by instructions requiring strict input validation and the use of parameterized queries.
Audit Metadata