omh-image-cards

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted data from external sources, including meetings, reports, PRs, and issues, to create visual summaries. It implements safety controls by defining 'visual evidence boundaries' and explicitly instructing the agent not to fabricate summaries or conclusions from raw source text.
  • [COMMAND_EXECUTION]: The skill references a platform-specific CLI tool (omh runtime record) for logging execution status. This usage is confined to internal workflow instrumentation and does not involve unsafe command construction or injection vectors.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:33 PM
Security Audit — agent-trust-hub — omh-image-cards