oma-debug

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data including error messages, logs, stack traces, and reproduction steps, creating a potential surface for indirect prompt injection.
  • Ingestion points: SKILL.md defines the input as error messages, failing behavior, logs, and test failures.
  • Boundary markers: There are no explicit instructions or delimiters to isolate untrusted data from the agent's core instructions.
  • Capability inventory: The skill utilizes CALL_TOOL for executing shell commands (tests, runtime) and WRITE for modifying source code and documentation.
  • Sanitization: The instructions do not specify any validation or sanitization protocols for the ingested error data before it is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:30 PM
Security Audit — agent-trust-hub — oma-debug