omh-running-work-board
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and display information from external local data sources, creating a potential surface for indirect instructions. \n
- Ingestion points: The skill instructions in
SKILL.mddirect the agent to "Read local dispatch and progress artifacts directly". \n - Boundary markers: The instructions lack explicit boundary markers or "ignore instructions" warnings for the data being read from local files. \n
- Capability inventory: Across
SKILL.md, the capabilities are restricted to reading local artifacts and rendering status information; no network, file-write, or shell execution tools are requested or used. \n - Sanitization: No sanitization, escaping, or validation logic is defined for the content extracted from the local artifacts.
Audit Metadata