omh-design-orchestration
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses an internal CLI tool (
omh) to record runtime records and delegation status (SKILL.md). - [INDIRECT_PROMPT_INJECTION]: The skill ingests user briefs and project context, creating an injection surface. It mitigates this by restricting persistent artifacts to closed vocabulary and opaque references (SKILL.md).
- Ingestion points: User briefs and project context in chat (SKILL.md).
- Boundary markers: Opaque context-reference boundaries (SKILL.md).
- Capability inventory:
omhruntime recording tool (SKILL.md). - Sanitization: Persisting only closed vocabulary and opaque metadata (SKILL.md).
- [SAFE]: Explicit safety guidelines in SKILL.md prohibit network services, browser launches, and external daemons.
Audit Metadata