omh-plan
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill provides a logical and governed framework for generating implementation plans. It enforces rigorous checks against project principles to ensure workflow integrity.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest requirements and repository-level documentation to generate plans. This is a functional requirement for planning tools and is managed by verification steps.
- Ingestion points: User-provided requirements, known facts, and constraints, as well as repository constitution files.
- Boundary markers: Employs structured output sections for goals, risks, and acceptance criteria to organize generated content.
- Capability inventory: Executes the
omhCLI for internal status recording and manages handoffs to downstream workflows. - Sanitization: Plans must satisfy MUST/SHOULD principles defined in a fixed-path constitution file before acceptance.
- [COMMAND_EXECUTION]: The skill includes a platform-specific command (
omh runtime record) used for workflow telemetry. The command uses static hardcoded arguments for skill state management and does not involve external network calls or sensitive file access.
Audit Metadata