omh-websearch-setup
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXFILTRATION]: The skill facilitates the configuration of API keys in local
.envfiles. It includes explicit safeguards requiring the redaction of secrets in user-facing diffs and restricts the agent to checking for key presence rather than reading secret values. - [INDIRECT_PROMPT_INJECTION]: The skill interacts with external configuration files (
.env). It mitigates prompt injection risks by requiring independent manual approval for each configuration change and using a structured diagnosis-guide-apply workflow. - [COMMAND_EXECUTION]: The workflow involves calling a local management tool (
omh) to record runtime status, which is a standard operation within its intended setup harness.
Audit Metadata