oma-pm

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as an intermediary that ingests untrusted data from user requests and codebase context to generate instructions (tasks and plans) for other AI agents. This creates a risk where malicious content in the processed data could be promoted into actionable tasks for downstream specialists.
  • Ingestion points: Processes 'User request, product goal, constraints, target users' and 'Existing codebase context, architecture constraints' as specified in SKILL.md and resources/execution-protocol.md.
  • Boundary markers: The skill lacks explicit boundary markers or instructions to disregard embedded directives within the files it analyzes from the codebase.
  • Capability inventory: The skill generates JSON plans and task-board markdown files (.agents/results/plan-*.json) that define the agent assignment, title, priority, and acceptance criteria for subsequent execution steps.
  • Sanitization: There is no evidence of sanitization, validation, or filtering of the ingested data before it is incorporated into the generated planning artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:30 PM
Security Audit — agent-trust-hub — oma-pm