oma-orchestrator

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The orchestrator utilizes shell wrappers such as spawn-agent.sh, parallel-run.sh, and verify.sh to invoke external CLI tools including claude, gemini, codex, qwen, cursor, kiro, and pi via the oma utility. These tools are granted access to the local filesystem and workspace to perform autonomous development tasks. \n- [PRIVILEGE_ESCALATION]: The configuration file config/cli-config.yaml explicitly enables flags that bypass standard security guardrails and user confirmation prompts for sub-agents. Examples include --dangerously-skip-permissions for Claude, --approval-mode=yolo for Gemini, --full-auto for Codex, and --trust-all-tools for Kiro. This configuration allows sub-agents to execute potentially destructive actions without human review or approval. \n- [INDIRECT_PROMPT_INJECTION]: The skill is a coordinator that ingests task descriptions and status reports from various sub-agents. This workflow is vulnerable to indirect prompt injection, where malicious output from one agent or untrusted task input could manipulate the orchestrator or subsequent agents in the pipeline. \n
  • Ingestion points: Data is ingested from task-board.md, progress-.md, and result-.md files stored in the memory path. \n
  • Boundary markers: The skill uses markdown headers in its prompt templates but lacks strong isolation or explicit warnings to ignore instructions embedded within sub-agent outputs. \n
  • Capability inventory: The orchestrator has the capability to spawn new processes (oma agent:spawn), write to the filesystem through memory tools, and trigger verification scripts. \n
  • Sanitization: There is no evidence of sanitization or validation of content returned by sub-agents before it is interpolated into future tasks or coordination steps.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 09:30 PM
Security Audit — agent-trust-hub — oma-orchestrator