omh-content-operator

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a shell command snippet omh runtime record to log the workflow status. This command is an internal tool used within the Hermes system for state tracking and orchestration.
  • [INDIRECT_PROMPT_INJECTION]: As a content operation skill, it is designed to ingest and process user-provided text. The skill implements several mitigation strategies including:
  • Ingestion points: Processes user request, target context, and source scope defined in SKILL.md.
  • Boundary markers: Includes explicit instructions for prepared-vs-observed boundaries and not-evidence boundaries to prevent the AI from confusing instructions with execution facts.
  • Capability inventory: Limited to executing the internal omh runtime logging tool.
  • Sanitization: Utilizes a no-invention rule, hallucination gates, and requirements for citations to validate source-backed content creation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:33 PM
Security Audit — agent-trust-hub — omh-content-operator