omh-achievements

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied queries and local telemetry artifacts (e.g., hermes_achievements_observation/v1) to generate summaries, creating a potential vulnerability surface.
  • Ingestion points: Processes external data from local plugin artifacts and user-provided queries as specified in SKILL.md.
  • Boundary markers: Explicit instructions require using 'not-evidence boundaries' and separating 'prepared guidance from observed platform evidence'.
  • Capability inventory: The skill body is instructional and does not include executable code or specific tool invocations in the analyzed file.
  • Sanitization: Lacks explicit data sanitization mechanisms, although the instructions mandate reporting missing observations as user-visible gaps rather than claiming completion.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:33 PM
Security Audit — agent-trust-hub — omh-achievements