omd-autopilot

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a set of internal JavaScript scripts (e.g., autopilot-mission.cjs, scripts/design-council-prime.cjs, autopilot-council-plan.cjs) to perform its design orchestration and validation tasks. It also interfaces with a platform-provided binary (omd) and an external authority controller specified via environment variables ($OMD_AUTHORITY_CONTROLLER_EXECUTABLE).
  • [SAFE]: The skill demonstrates best practices for design system management, including a formal derivation chain for tokens and strict adherence to accessibility (ARIA) and visual quality standards. It includes built-in quality gates ('slop gates') to prevent the generation of low-quality UI patterns. No evidence of prompt injection, data exfiltration, or unauthorized remote code execution was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 08:35 AM
Security Audit — agent-trust-hub — omd-autopilot