omh-achievements
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied queries and local telemetry artifacts (e.g., hermes_achievements_observation/v1) to generate summaries, creating a potential vulnerability surface.
- Ingestion points: Processes external data from local plugin artifacts and user-provided queries as specified in SKILL.md.
- Boundary markers: Explicit instructions require using 'not-evidence boundaries' and separating 'prepared guidance from observed platform evidence'.
- Capability inventory: The skill body is instructional and does not include executable code or specific tool invocations in the analyzed file.
- Sanitization: Lacks explicit data sanitization mechanisms, although the instructions mandate reporting missing observations as user-visible gaps rather than claiming completion.
Audit Metadata