omh-agent-evaluation

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements a structured, evidence-based evaluation workflow with explicit safety rules that warn against the use of secrets, private data, or production tasks in evaluation benchmarks.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external run artifacts and task fixtures, which represents an ingestion surface. 1. Ingestion points: The skill requires 'observed run artifacts' and 'task set and fixtures' as primary inputs for evaluation (SKILL.md). 2. Boundary markers: The skill instructions do not specify any delimiters or boundary markers for the interpolation of these external inputs. 3. Capability inventory: The skill is primarily instructional and focused on summarization; it does not demonstrate or request dangerous capabilities such as unauthorized file writes or arbitrary network exfiltration. 4. Sanitization: No explicit logic is provided for sanitizing, validating, or escaping the external artifact data before it is analyzed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:33 PM
Security Audit — agent-trust-hub — omh-agent-evaluation