omh-capability-toggle

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's instructions and metadata demonstrate a clear, legitimate purpose for managing local capability policies without evidence of malicious intent, credential harvesting, or unauthorized network operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill functions by ingesting user prompts to modify local system configuration, creating a potential attack surface. However, the risk is mitigated by explicit instructions requiring the use of canonical IDs for families and mandatory user clarification when inputs are ambiguous, ensuring the agent does not perform unintended actions based on imprecise user data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:33 PM
Security Audit — agent-trust-hub — omh-capability-toggle