omh-harness-session-inventory
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, prompt injections, or unauthorized command executions were detected. The CLI tools referenced ('omh') are part of the vendor's internal ecosystem.- [INDIRECT_PROMPT_INJECTION]: The skill processes session metadata from multiple sources (Codex, Claude Code, Hermes). It mitigates injection risks by defining mandatory 'evidence boundaries' and separating prepared guidance from observed data.- [DATA_EXPOSURE]: Security instructions within the skill require that all configuration drift reports and inventories be 'secret-redacted', ensuring sensitive credentials are not exposed in the session metadata inventory.
Audit Metadata