model-onboarding

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its requirement to process and follow instructions from external research materials and community-contributed content.
  • Ingestion points: The skill reads docs/MODEL-ONBOARDING.md, MODEL_OPTI.md, and external research dossiers under .omc/research/ which include vendor documentation and community harnesses.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard potentially malicious instructions embedded within the research data.
  • Capability inventory: The skill utilizes the Bash tool for command execution (e.g., omh, hermes) and the Edit and Write tools for code modifications, creating a significant impact surface if injected instructions are followed.
  • Sanitization: No sanitization or validation mechanisms are described for handling the content retrieved from external sources before it influences the agent's actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 06:25 PM
Security Audit — agent-trust-hub — model-onboarding