oma-dev-workflow

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONPERSISTENCECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the user to install the mise tool by piping a script from a remote URL directly into a shell (curl https://mise.run | sh). This is the official installation method for the tool but carries inherent risks associated with piping remote content to a shell environment.
  • [PERSISTENCE]: The skill automates the modification of the user's shell configuration file (~/.zshrc) to ensure the mise environment is automatically activated in every new terminal session.
  • [PERSISTENCE]: The skill includes instructions and automation logic to install several Git hooks into the repository's .git/hooks directory (commit-msg, pre-commit, pre-push) which execute automated validation scripts during the development lifecycle.
  • [COMMAND_EXECUTION]: The skill defines and executes various development tasks using the mise task runner, including database migrations via alembic, Docker container management, and code generation via tools like orval.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection by reading and acting upon external files such as mise.toml, Git logs, and CI/CD configuration files. Ingestion points: mise.toml task definitions, Git commit logs, and command execution logs in SKILL.md and resources/validation-pipeline.md. Boundary markers: The skill instructions provide guardrails against hardcoding secrets but do not specify explicit delimiters or 'ignore instructions' wrappers when processing log files or external task definitions. Capability inventory: Includes shell command execution, file system writes for configuration/hooks, and network access through integrated developer tools across all referenced resource files. Sanitization: The skill does not implement specific sanitization or validation routines for the content of processed configuration files, relying on the user to review unfamiliar tasks.
Recommendations
  • HIGH: Downloads and executes remote code from: https://mise.run - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 09:31 PM
Security Audit — agent-trust-hub — oma-dev-workflow