omd-slop-audit

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection because it is designed to ingest and analyze untrusted external data, specifically UI copy and source code (DOM/CSS/JSX) from web routes.
  • Ingestion points: Processes project-specific documentation (DESIGN.md, .omd/preferences.md) and actual product routes during the AUDIT and APPLY phases.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands within the ingested content are defined in the skill instructions.
  • Capability inventory: The skill itself contains no executable scripts or subprocess calls; however, it is intended to guide an agent that possesses file-read, file-write, and web-access capabilities.
  • Sanitization: There are no mentions of escaping, validation, or filtering of the external content being audited.
  • [SAFE]: The skill references several external resources from well-known technology companies, international standards organizations, and government design systems (including Apple, Microsoft, Atlassian, the W3C, and the UK and US governments) to provide a basis for its audit taxonomy. These references are used strictly for documentation and methodology and do not involve the download or execution of remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 02:09 PM
Security Audit — agent-trust-hub — omd-slop-audit