omh-cto-loop
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a structured leadership workflow without implementing any dangerous functionality. The instructions focus on decision-making processes and role definitions within the Hermes framework.
- [COMMAND_EXECUTION]: The skill utilizes the platform-specific
omh runtime recordcommand to manage and record the state of the workflow. This is a local administrative tool call intended for status monitoring and does not involve untrusted network data or shell injection risks. - [INDIRECT_PROMPT_INJECTION]: The skill ingests external data such as 'operating signals' and 'known risks'. While this presents a potential surface for indirect injection, the skill is constrained by a decision-gated quality tier and does not possess high-privilege capabilities that would allow for automated exploitation.
Audit Metadata