omh-data-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill references a shell command
omh runtime recordused to track the lifecycle and status of the data analysis task. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and analyze external datasets (CSV, JSON, logs), which could contain malicious instructions designed to influence the agent.
- Ingestion points: Processes user-supplied datasets, tables, CSV files, JSON data, and system logs as described in the workflow lane.
- Boundary markers: Includes 'not-evidence boundaries' and 'prepared-vs-observed' boundaries to distinguish between intended guidance and actual data observations.
- Capability inventory: Executes the
omhCLI tool for runtime state recording. - Sanitization: Employs 'hallucination guards' and 'causal-claim guards' to limit unsupported claims, though specific sanitization of input data content is not detailed.
Audit Metadata