oma-qa
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted codebase data (source code, diffs, and project configurations) and external tool outputs as its primary input for auditing. It lacks explicit boundary markers or instructions to treat this content purely as data, creating a potential surface for indirect prompt injection if malicious instructions are embedded in the code under review. However, the skill includes a strong guardrail prohibiting the agent from making implementation changes, limiting the potential impact of such an attack.
- Ingestion points: The skill reads source files and diffs via the
CODEBASEscope and reviewer instructions viaUSER_DATAinSKILL.md. - Boundary markers: Absent. There are no specific delimiters defined to wrap untrusted codebase content.
- Capability inventory: The agent has access to shell commands (
CALL_TOOL), codebase exploration tools (Serena MCP), and browser automation (Chrome DevTools MCP). - Sanitization: No explicit sanitization or filtering logic is defined for the ingested codebase content.
- [DYNAMIC_EXECUTION]: The skill utilizes the
evaluate_scriptprimitive within a browser context to perform runtime verification, such as inspecting DOM state and testing rate limiting through fetch calls. - Evidence: Instructions in
resources/execution-protocol.mddirect the agent to useevaluate_script(function)for inspection andevaluate_script(fetch)for API verification. - Context: The execution is mandated to occur within an isolated browser context (
isolatedContext: "qa-test"), which mitigates risks of session contamination and restricts the scope to the specific test environment.
Audit Metadata