omh-skill-scout

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute the omh runtime record command in the shell to track workflow status. This command is a project-specific utility for the 'oh-my-hermes' platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external sources such as GitHub, web searches, and marketplaces during the skill discovery phase.
  • Ingestion points: External search results, repository metadata, and candidate skill content identified during search.
  • Boundary markers: The instructions include explicit 'Safety rules' and 'Do Not Use When' sections that warn the agent not to trust external sources by default or claim implementation evidence from prepared guidance.
  • Capability inventory: The skill performs status recording via the omh CLI tool (SKILL.md). It does not specify generic file-writing or network-exfiltration capabilities in the provided instructions.
  • Sanitization: The workflow requires the creation of a 'risk review' and a 'decision matrix' to identify trust gaps, emphasizing manual review over automated adoption.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:34 PM
Security Audit — agent-trust-hub — omh-skill-scout