oma-debug
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data including error messages, logs, stack traces, and reproduction steps, creating a potential surface for indirect prompt injection.
- Ingestion points: SKILL.md defines the input as error messages, failing behavior, logs, and test failures.
- Boundary markers: There are no explicit instructions or delimiters to isolate untrusted data from the agent's core instructions.
- Capability inventory: The skill utilizes CALL_TOOL for executing shell commands (tests, runtime) and WRITE for modifying source code and documentation.
- Sanitization: The instructions do not specify any validation or sanitization protocols for the ingested error data before it is processed.
Audit Metadata