skills/rlaope/oh-my-hermes/ulw-work/Gen Agent Trust Hub

ulw-work

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied implementation plans and generates sub-prompts for parallel execution lanes, creating an attack surface for instructions embedded in external data.\n
  • Ingestion points: The skill ingests user-provided "accepted implementation plans" (SKILL.md).\n
  • Boundary markers: It enforces structured prompt formats (TASK, DELIVERABLE, SCOPE, VERIFY, STOP WHEN) to delimit instructions and reduce accidental obedience (references/dependency-topology.md).\n
  • Capability inventory: The skill utilizes task delegation and board tools capable of file modification and command execution (SKILL.md, references/kanban-lane.md).\n
  • Sanitization: It mandates the use of omh handoff-risk-scan to inspect brief files before handoff to identify high-risk content (SKILL.md).\n- [COMMAND_EXECUTION]: The workflow involves executing various CLI tools for orchestration, task dispatching, and system verification.\n
  • Evidence: Mentions commands for omh coding campaign, omh handoff-risk-scan, claude, and codex (SKILL.md, references/campaign-orchestrator.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:35 PM
Security Audit — agent-trust-hub — ulw-work