omh-performance-goal

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the omh command-line utility for runtime recording and tracking the status of performance optimization tasks, which is appropriate for its stated purpose.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-supplied benchmark command and metric inputs. While this is a necessary part of the optimization workflow, it constitutes an indirect injection surface if untrusted commands are provided.\n
  • Ingestion points: Metrics and benchmark commands defined in the workflow target.\n
  • Boundary markers: The instructions require explicitly naming the workflow target, evidence boundary, and stop conditions.\n
  • Capability inventory: Shell command execution via the omh runtime harness.\n
  • Sanitization: The skill instructions do not specify a validation or sanitization mechanism for the benchmark commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:51 AM
Security Audit — agent-trust-hub — omh-performance-goal