oma-qa

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted codebase data (source code, diffs, and project configurations) and external tool outputs as its primary input for auditing. It lacks explicit boundary markers or instructions to treat this content purely as data, creating a potential surface for indirect prompt injection if malicious instructions are embedded in the code under review. However, the skill includes a strong guardrail prohibiting the agent from making implementation changes, limiting the potential impact of such an attack.
  • Ingestion points: The skill reads source files and diffs via the CODEBASE scope and reviewer instructions via USER_DATA in SKILL.md.
  • Boundary markers: Absent. There are no specific delimiters defined to wrap untrusted codebase content.
  • Capability inventory: The agent has access to shell commands (CALL_TOOL), codebase exploration tools (Serena MCP), and browser automation (Chrome DevTools MCP).
  • Sanitization: No explicit sanitization or filtering logic is defined for the ingested codebase content.
  • [DYNAMIC_EXECUTION]: The skill utilizes the evaluate_script primitive within a browser context to perform runtime verification, such as inspecting DOM state and testing rate limiting through fetch calls.
  • Evidence: Instructions in resources/execution-protocol.md direct the agent to use evaluate_script(function) for inspection and evaluate_script(fetch) for API verification.
  • Context: The execution is mandated to occur within an isolated browser context (isolatedContext: "qa-test"), which mitigates risks of session contamination and restricts the scope to the specific test environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:30 PM
Security Audit — agent-trust-hub — oma-qa