oma-design

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches design templates and package metadata from well-known sources, specifically the official NPM registry (registry.npmjs.org) and the community-maintained getdesign catalog (getdesign.md). These downloads are restricted to the skill's primary functional scope.
  • [COMMAND_EXECUTION]: Utilizes shell commands including bunx, curl, and tar to resolve dependencies and retrieve design seeds. The workflow includes automated integrity verification where fetched content is validated against SHA256 hashes defined in a manifest.
  • [PROMPT_INJECTION]: Addresses the risk of indirect prompt injection from untrusted external markdown (vendor templates) by implementing framing defenses. These instructions explicitly direct the agent to treat ingested data as reference-only and to ignore any embedded imperative commands or role-play instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 06:54 AM
Security Audit — agent-trust-hub — oma-design