omh-performance-goal
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
omhcommand-line utility for runtime recording and tracking the status of performance optimization tasks, which is appropriate for its stated purpose.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-suppliedbenchmark commandandmetricinputs. While this is a necessary part of the optimization workflow, it constitutes an indirect injection surface if untrusted commands are provided.\n - Ingestion points: Metrics and benchmark commands defined in the workflow target.\n
- Boundary markers: The instructions require explicitly naming the workflow target, evidence boundary, and stop conditions.\n
- Capability inventory: Shell command execution via the
omhruntime harness.\n - Sanitization: The skill instructions do not specify a validation or sanitization mechanism for the benchmark commands.
Audit Metadata