omh-instinct-ledger

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data, including repeated observations, user corrections, and workflow lessons, to generate 'instinct candidates' and plans.
  • Ingestion points: Data enters the context through the 'user request', 'target context', and 'observed evidence' parameters specified in the catalog metadata (SKILL.md).
  • Boundary markers: The skill includes a 'Safety rules' section and a 'Quality bar' that explicitly instruct the agent to separate prepared guidance from observed runtime evidence and to avoid automatic actions like hook installation or memory mutation.
  • Capability inventory: While the skill body describes generating plans and reviews (e.g., instinct_ledger_plan/v1), it does not list any high-risk tools in the frontmatter or include scripts with direct shell execution capabilities, limiting the potential impact of an injection.
  • Sanitization: There are no explicit instructions for sanitizing or escaping the incoming text before it is interpolated into the workflow artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:33 PM
Security Audit — agent-trust-hub — omh-instinct-ledger