skills/rlaope/oh-my-hermes/omh-plan/Gen Agent Trust Hub

omh-plan

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill provides a logical and governed framework for generating implementation plans. It enforces rigorous checks against project principles to ensure workflow integrity.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest requirements and repository-level documentation to generate plans. This is a functional requirement for planning tools and is managed by verification steps.
  • Ingestion points: User-provided requirements, known facts, and constraints, as well as repository constitution files.
  • Boundary markers: Employs structured output sections for goals, risks, and acceptance criteria to organize generated content.
  • Capability inventory: Executes the omh CLI for internal status recording and manages handoffs to downstream workflows.
  • Sanitization: Plans must satisfy MUST/SHOULD principles defined in a fixed-path constitution file before acceptance.
  • [COMMAND_EXECUTION]: The skill includes a platform-specific command (omh runtime record) used for workflow telemetry. The command uses static hardcoded arguments for skill state management and does not involve external network calls or sensitive file access.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:34 PM
Security Audit — agent-trust-hub — omh-plan