omh-lifecycle-growth
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns detected. The skill instructions follow best practices for secure execution and risk management.
- [COMMAND_EXECUTION]: The skill utilizes an internal CLI tool (
omh) to create metadata artifacts as part of its growth experiment planning. This is a functional requirement and is not used for unauthorized system access. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted inputs such as JSON data and event schemas. This ingestion surface is mitigated by comprehensive safety rules, 'fail-closed' validation for missing inputs, and a requirement for human approval before any launch. Evidence Chain: (1) Ingestion point: JSON data provided to the
buildcommand; (2) Boundary markers: Explicit instructions to 'HOLD' when inputs are incomplete or validation fails; (3) Capability inventory: Command execution limited to theomhCLI; (4) Sanitization: Strict eligibility checks and safety policies enforced in the procedure files.
Audit Metadata