om-backlog
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill identifies and mitigates risks associated with processing untrusted data from product briefs, specs, and tracker issues.
- Ingestion points: The
{source}file and tracker data (issue bodies and comments) loaded during the workflow. - Boundary markers: Explicit instructions in
references/agentic-setup.mdcommand the agent to treat repo and tracker content as data only, ignoring and reporting any embedded instructions like "ignore previous instructions." - Capability inventory: Tracker modification via
update-issue,comment-issue, and theom-prepare-issuetool. - Sanitization: Mandatory regex validation and quoting for all externally-sourced values used in shell or path interpolation.
- Human Review: A required confirmation step (HARD-GATE) ensures no issues are filed without user approval of the exact content.
- [COMMAND_EXECUTION]: The skill interacts with the local environment using predefined companion tools.
- Safety: Execution is limited to tools in the locally installed collection (e.g.,
om-prepare-issue). Input validation rules are provided to prevent command injection by sanitizing IDs and paths from the tracker or source files.
Audit Metadata