omd-slop-audit
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection because it is designed to ingest and analyze untrusted external data, specifically UI copy and source code (DOM/CSS/JSX) from web routes.
- Ingestion points: Processes project-specific documentation (
DESIGN.md,.omd/preferences.md) and actual product routes during theAUDITandAPPLYphases. - Boundary markers: No specific delimiters or instructions to ignore embedded commands within the ingested content are defined in the skill instructions.
- Capability inventory: The skill itself contains no executable scripts or subprocess calls; however, it is intended to guide an agent that possesses file-read, file-write, and web-access capabilities.
- Sanitization: There are no mentions of escaping, validation, or filtering of the external content being audited.
- [SAFE]: The skill references several external resources from well-known technology companies, international standards organizations, and government design systems (including Apple, Microsoft, Atlassian, the W3C, and the UK and US governments) to provide a basis for its audit taxonomy. These references are used strictly for documentation and methodology and do not involve the download or execution of remote code.
Audit Metadata