omh-people-ops

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill defines a fair and evidence-based workflow for hiring decisions. It includes explicit safety constraints, such as keeping protected characteristics out of evaluations and avoiding unauthorized external HR actions.
  • [NO_CODE]: This skill consists entirely of instructional markdown and metadata. There are no executable scripts or external dependencies included that could perform unauthorized operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted hiring and candidate data, creating a potential surface for indirect prompt injection. However, the lack of exploitable tools or capabilities makes the risk level safe.
  • Ingestion points: Recruiting plans, candidate debriefs, and hiring context provided in user prompts (SKILL.md).
  • Boundary markers: No specific delimiters or safety instructions are defined for user-provided evidence.
  • Capability inventory: No scripts or tools for file system, network, or command execution are included.
  • Sanitization: No input validation or sanitization is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:34 PM
Security Audit — agent-trust-hub — omh-people-ops