omh-operating-rhythm

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a shell command template 'omh runtime record' for logging workflow status. This is a standard operational command within the framework environment and does not involve external network requests or unsafe parameter handling.\n- [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted external data in the form of meeting notes and scrum records (Ingestion points). It incorporates safety rules to distinguish between prepared records and observed evidence (Boundary markers). The skill's capabilities are limited to producing artifacts and logging status via the framework CLI (Capability inventory). No explicit sanitization of the input text is mentioned, but the constrained execution environment mitigates risk (Sanitization).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:34 PM
Security Audit — agent-trust-hub — omh-operating-rhythm