teach-oh
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from the project codebase, including documentation and commit history, which are potentially untrusted sources.\n
- Ingestion points: SKILL.md (Step 1) instructs the agent to read README, CONTRIBUTING, CLAUDE.md, ADRs, and recent commits.\n
- Boundary markers: The process includes a mandatory human-in-the-loop step where the agent must present the draft for user approval before writing to the filesystem.\n
- Capability inventory: The skill has capabilities to write to the project's AGENTS.md file and, if requested, install additional agent files and hooks to .omp/ and .claude/ directories.\n
- Sanitization: There is no explicit sanitization of the ingested content; safety relies on standard model guardrails and user review of the generated output.\n- [EXTERNAL_DOWNLOADS]: The skill facilitates the download of additional configuration and executable hooks from the author's official GitHub repository.\n
- Source: Fetches resources from https://raw.githubusercontent.com/open-horizon-labs/skills.\n
- Verification: The instructions recommend using specific release tags or commit SHAs and suggest verifying checksums if available.\n
- Resource type: Downloads include markdown agent definitions and a TypeScript hook (oh-skills-phase.ts) for phase-aware task management.
Audit Metadata