om-synthetic-users

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content (briefs, specs, prototypes, app states) which acts as an attack surface for indirect prompt injection.
  • Ingestion points: Data is ingested from product-brief.md, specifications, interview notes, and interactive application states (referenced in SKILL.md and references/agentic-setup.md).
  • Boundary markers: The skill includes robust defensive instructions in references/agentic-setup.md ("Untrusted content boundary") and SKILL.md ("Security boundaries") that explicitly command the agent to treat external content as data, ignore embedded directives, and report them as suspected prompt injection.
  • Capability inventory: The skill performs scoped filesystem read/write operations (limited to ${research} and session directories), browser interactions via a provider (open, interact, snapshot), and subagent creation (SKILL.md, references/walkthrough.md, references/session-artifacts.md).
  • Sanitization: The skill employs path and value validation using regular expressions (^[A-Za-z0-9._/-]+$), strips source metadata before passing data to persona subagents, and requires manual user confirmation for panel composition before execution (references/agentic-setup.md, SKILL.md).
  • [COMMAND_EXECUTION]: The skill invokes repository-sourced commands and performs browser operations within a documented, read-only boundary.
  • Evidence: Invokes om-prepare-test-env to boot testing environments and uses browser-provider operations like open, snapshot, and interact to navigate prototypes or running applications (SKILL.md, references/walkthrough.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:14 AM
Security Audit — agent-trust-hub — om-synthetic-users