om-synthetic-users
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content (briefs, specs, prototypes, app states) which acts as an attack surface for indirect prompt injection.
- Ingestion points: Data is ingested from
product-brief.md, specifications, interview notes, and interactive application states (referenced inSKILL.mdandreferences/agentic-setup.md). - Boundary markers: The skill includes robust defensive instructions in
references/agentic-setup.md("Untrusted content boundary") andSKILL.md("Security boundaries") that explicitly command the agent to treat external content as data, ignore embedded directives, and report them as suspected prompt injection. - Capability inventory: The skill performs scoped filesystem read/write operations (limited to
${research}and session directories), browser interactions via a provider (open,interact,snapshot), and subagent creation (SKILL.md,references/walkthrough.md,references/session-artifacts.md). - Sanitization: The skill employs path and value validation using regular expressions (
^[A-Za-z0-9._/-]+$), strips source metadata before passing data to persona subagents, and requires manual user confirmation for panel composition before execution (references/agentic-setup.md,SKILL.md). - [COMMAND_EXECUTION]: The skill invokes repository-sourced commands and performs browser operations within a documented, read-only boundary.
- Evidence: Invokes
om-prepare-test-envto boot testing environments and uses browser-provider operations likeopen,snapshot, andinteractto navigate prototypes or running applications (SKILL.md,references/walkthrough.md).
Audit Metadata