omh-skill-scout
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute the
omh runtime recordcommand in the shell to track workflow status. This command is a project-specific utility for the 'oh-my-hermes' platform. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external sources such as GitHub, web searches, and marketplaces during the skill discovery phase.
- Ingestion points: External search results, repository metadata, and candidate skill content identified during search.
- Boundary markers: The instructions include explicit 'Safety rules' and 'Do Not Use When' sections that warn the agent not to trust external sources by default or claim implementation evidence from prepared guidance.
- Capability inventory: The skill performs status recording via the
omhCLI tool (SKILL.md). It does not specify generic file-writing or network-exfiltration capabilities in the provided instructions. - Sanitization: The workflow requires the creation of a 'risk review' and a 'decision matrix' to identify trust gaps, emphasizing manual review over automated adoption.
Audit Metadata