skills/rlaope/oh-my-hermes/omh-decide/Gen Agent Trust Hub

omh-decide

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a local runtime command omh runtime record to track workflow status and delegation results within the Hermes environment. This command is used for operational logging and monitoring of the agent's progress during strategic synthesis.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external inputs such as user-defined goals and evidence to generate strategy briefs, which presents a surface for indirect prompt injection.
  • Ingestion points: External data enters through user prompts providing 'goal', 'known evidence', and 'constraints' defined in SKILL.md.
  • Boundary markers: The instructions explicitly require separating observed signals from strategic inference and demand that recommendations be tied to observed evidence.
  • Capability inventory: The skill has the capability to write decision records to the docs/adr/ directory.
  • Sanitization: The skill implements a strong procedural safeguard requiring explicit user approval before any file is written to the system, ensuring the user remains in the loop for all filesystem modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 01:30 PM
Security Audit — agent-trust-hub — omh-decide