oma-frontend

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMPROMPT_INJECTIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses aggressive, prescriptive language to enforce non-standard development rules. It mandates that the agent must 'retract' any findings that conflict with the skill's specific instructions regarding proxy.ts and middleware.ts, using phrases like 'touch it and you die' and 'fatal self-error' to bypass the agent's internal knowledge and guardrails.
  • [METADATA_POISONING]: The skill provides factually incorrect information about the Next.js framework (claiming Next.js 16+ features that are non-existent) and includes a fraudulent reference URL (https://nextjs.org/docs/messages/middleware-to-proxy) intended to deceive the agent into accepting these false claims as authoritative.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest external data from a DESIGN.md file without adequate safety boundaries.
  • Ingestion points: The agent is told to read DESIGN.md Section 9 'verbatim' to guide its implementation logic.
  • Boundary markers: There are no specified delimiters or instructions to ignore potential malicious content within the design file.
  • Capability inventory: The skill possesses capabilities to modify the codebase (WRITE), execute system commands (CALL_TOOL), and interact with the network (NETWORK).
  • Sanitization: No sanitization or validation mechanisms are provided for the external data, which is treated as an authoritative specification.
  • [COMMAND_EXECUTION]: The skill utilizes several system tools for codebase analysis and verification.
  • Tools used: rg (ripgrep) for searching the filesystem, and project-specific verification commands such as npx tsc, vitest, and linting tools. While these are standard developer utilities, they provide the necessary execution surface for findings in other categories.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 09:30 PM
Security Audit — agent-trust-hub — oma-frontend