oma-pm
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill acts as an intermediary that ingests untrusted data from user requests and codebase context to generate instructions (tasks and plans) for other AI agents. This creates a risk where malicious content in the processed data could be promoted into actionable tasks for downstream specialists.
- Ingestion points: Processes 'User request, product goal, constraints, target users' and 'Existing codebase context, architecture constraints' as specified in
SKILL.mdandresources/execution-protocol.md. - Boundary markers: The skill lacks explicit boundary markers or instructions to disregard embedded directives within the files it analyzes from the codebase.
- Capability inventory: The skill generates JSON plans and task-board markdown files (
.agents/results/plan-*.json) that define the agent assignment, title, priority, and acceptance criteria for subsequent execution steps. - Sanitization: There is no evidence of sanitization, validation, or filtering of the ingested data before it is incorporated into the generated planning artifacts.
Audit Metadata