omh-data-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill references a shell command omh runtime record used to track the lifecycle and status of the data analysis task.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and analyze external datasets (CSV, JSON, logs), which could contain malicious instructions designed to influence the agent.
  • Ingestion points: Processes user-supplied datasets, tables, CSV files, JSON data, and system logs as described in the workflow lane.
  • Boundary markers: Includes 'not-evidence boundaries' and 'prepared-vs-observed' boundaries to distinguish between intended guidance and actual data observations.
  • Capability inventory: Executes the omh CLI tool for runtime state recording.
  • Sanitization: Employs 'hallucination guards' and 'causal-claim guards' to limit unsupported claims, though specific sanitization of input data content is not detailed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:33 PM
Security Audit — agent-trust-hub — omh-data-analysis