omh-refactor-plan
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection due to its requirement to ingest and analyze untrusted external data. \n- Ingestion points: As described in
SKILL.mdandreferences/dependency-upgrade.md, the workflow reads repository evidence, import graphs, upstream migration guides, and license files from the project environment. \n- Boundary markers: The skill's instructions lack explicit delimiters or 'ignore' directives for the processing of external textual data, increasing the risk of the agent following instructions embedded within those files. \n- Capability inventory: This skill is scoped to planning and reconnaissance; it does not perform network operations, file writes, or command execution directly, delegating these tasks to a separate execution lane that is human-approved. \n- Sanitization: No mechanisms for the sanitization or validation of content from external migration guides or code artifacts are defined in the workflow.
Audit Metadata