ulw-context

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes terminology from repository files like PROJECT_TERMS.md, which creates a potential surface for indirect injection. 1. Ingestion points: Reads PROJECT_TERMS.md and repository source code (documented in SKILL.md and references/project-terms.md). 2. Boundary markers: Explicitly mandates that external prose has 'zero direct routing or machine authority' and treats the file as optional source prose. 3. Capability inventory: Limited to state recording via the 'omh' CLI and candidate staging, which requires explicit human confirmation (documented in SKILL.md). 4. Sanitization: Strict rules prevent definitions, localized labels, or guidance from being used as routing triggers, anti-triggers, or dispatch inputs.
  • [COMMAND_EXECUTION]: The skill uses the 'omh runtime record' command for state management within its execution harness. This is a local platform-specific utility for workflow observability and does not present evidence of unauthorized behavior, network exfiltration, or security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:34 PM
Security Audit — agent-trust-hub — ulw-context