omh-finance-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions focus on performing bounded financial analysis and explicitly prohibit the agent from implying or performing authoritative actions in accounting, banking, or tax systems.
  • [COMMAND_EXECUTION]: The skill uses the omh CLI tool for runtime instrumentation and telemetry. These commands are static, used for recording workflow evidence within the ops-review harness, and do not incorporate untrusted external input.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external financial data such as ledgers and budget reports. Although it lacks explicit boundary markers for this data, the risk is negligible as the skill lacks exploitable capabilities such as arbitrary file writes or network access, and it defines rigorous internal validation and reconciliation procedures.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:33 PM
Security Audit — agent-trust-hub — omh-finance-analysis