omh-award-bar-score
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates entirely through instructional prompts and static reference data without any shell command execution or persistence mechanisms.
- [SAFE]: No obfuscation, Base64 encoding, or hidden URLs were detected in the provided markdown or reference files.
- [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for processing external web surfaces, but it lacks execution capabilities that could be exploited via injection. It includes clear boundary markers and safety rules that define the assessment as a non-binding rubric self-assessment.
- Ingestion points: Target URLs and rendered captures processed via internal routing.
- Boundary markers: Explicit safety instructions stating self-assessments are not jury outcomes and prohibiting the scoring of unrendered pages.
- Capability inventory: Limited to arithmetic calculation and artifact generation; no network or subprocess capabilities.
- Sanitization: Instructions require citing the source body and date for all quoted weights and thresholds.
Audit Metadata