skills/open-mercato/skills/om-backlog/Gen Agent Trust Hub

om-backlog

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies and mitigates risks associated with processing untrusted data from product briefs, specs, and tracker issues.
  • Ingestion points: The {source} file and tracker data (issue bodies and comments) loaded during the workflow.
  • Boundary markers: Explicit instructions in references/agentic-setup.md command the agent to treat repo and tracker content as data only, ignoring and reporting any embedded instructions like "ignore previous instructions."
  • Capability inventory: Tracker modification via update-issue, comment-issue, and the om-prepare-issue tool.
  • Sanitization: Mandatory regex validation and quoting for all externally-sourced values used in shell or path interpolation.
  • Human Review: A required confirmation step (HARD-GATE) ensures no issues are filed without user approval of the exact content.
  • [COMMAND_EXECUTION]: The skill interacts with the local environment using predefined companion tools.
  • Safety: Execution is limited to tools in the locally installed collection (e.g., om-prepare-issue). Input validation rules are provided to prevent command injection by sanitizing IDs and paths from the tracker or source files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:14 AM
Security Audit — agent-trust-hub — om-backlog