omh-production-audit

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes a platform-specific CLI tool using the command omh runtime record to log skill status and harness information during the audit process.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external release evidence, test results, and CI/CD artifacts which could contain adversarial instructions.
  • Ingestion points: The skill processes 'known test, CI, deploy, observability, security, and support evidence' as specified in the Required Inputs section.
  • Boundary markers: The skill output includes a 'not-evidence boundary' intended to separate verified data from unverified claims, though its effectiveness against adversarial injection is not defined.
  • Capability inventory: The skill uses a shell-based status recorder (omh) and has the capability to generate multi-part reports (readiness matrix, risk register); it explicitly prohibits infrastructure and credential modifications.
  • Sanitization: There are no instructions for sanitizing or escaping the content of the external evidence artifacts before they are incorporated into the audit results.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:34 PM
Security Audit — agent-trust-hub — omh-production-audit