om-setup-discovery-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from repository files and tracker data which are considered untrusted ingestion points. It mitigates this risk by establishing a strict 'Untrusted content boundary' policy.\n
- Ingestion points: Reads
SDLC.md,AGENTS.md, and tracker-derived work data.\n - Boundary markers: Explicit instructions in
references/agentic-setup.mdmandate that the agent ignore embedded directives and report them as suspected injections.\n - Capability inventory: The skill is authorized to perform file writes to
SDLC.mdand configuration files, create directories, and executegitoperations.\n - Sanitization: Configuration paths such as
paths.specsare validated using a restricted alphanumeric regex to prevent path traversal attacks.\n- [COMMAND_EXECUTION]: The skill utilizes standard system utilities includinggitandjqto manage repository state and configuration files. These commands are localized to the documented setup workflow and intended repository maintenance.\n- [EXTERNAL_DOWNLOADS]: The skill identifies missing companion skills and provides the operator withnpxcommand templates to facilitate manual installation from external package registries. These are provided as informational recommendations for the user.\n- [PROMPT_INJECTION]: Text patterns resembling prompt injection (e.g., 'ignore previous instructions') are included in the documentation purely as examples of malicious patterns that the agent is instructed to identify and disregard when processing repository content.
Audit Metadata