omh-websearch-setup

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill facilitates the configuration of API keys in local .env files. It includes explicit safeguards requiring the redaction of secrets in user-facing diffs and restricts the agent to checking for key presence rather than reading secret values.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with external configuration files (.env). It mitigates prompt injection risks by requiring independent manual approval for each configuration change and using a structured diagnosis-guide-apply workflow.
  • [COMMAND_EXECUTION]: The workflow involves calling a local management tool (omh) to record runtime status, which is a standard operation within its intended setup harness.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:34 PM
Security Audit — agent-trust-hub — omh-websearch-setup