omh-frontend

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill demonstrates security best practices by explicitly prohibiting the agent from invoking external design, image, or network services, and by restricting the use of third-party LLMs from the core execution environment.
  • [INDIRECT_PROMPT_INJECTION]: The workflow is designed to process user-supplied design prompts and visual references. While this creates a surface for indirect instructions, the skill mitigates risk by requiring structured design contracts (DESIGN.md) and human-in-the-loop review cycles for all rendered evidence.
  • [COMMAND_EXECUTION]: The instructions involve the use of a local 'omh' CLI utility for status recording and design metadata retrieval. These commands are scoped to the local environment and are intended for retrieving curated design tokens without external dependencies.
  • [EXTERNAL_DOWNLOADS]: The skill documentation references third-party libraries such as Lenis and GSAP for scroll motion. The instructions explicitly mandate that these packages must not be fetched or installed automatically by the agent, ensuring all dependency management remains subject to user oversight.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:33 PM
Security Audit — agent-trust-hub — omh-frontend