skills/simota/agent-skills/omen/Gen Agent Trust Hub

omen

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill configuration explicitly instructs the agent to bypass security permission checks when executing external tools.
  • Evidence: The reference documentation for the tri-engine failure recipe (reference/tri-engine-failure.md) specifies that the agy sub-agent must be executed using the command agy -p "<prompt>" --dangerously-skip-permissions. This flag is explicitly intended to override safety and permission constraints in the target environment.
  • [DYNAMIC_EXECUTION]: The skill dynamically constructs and executes shell commands for sub-agents at runtime based on contextual input.
  • Evidence: As detailed in reference/tri-engine-failure.md, the multi recipe generates command strings for codex exec and agy -p. This runtime assembly of executable commands increases the risk of command injection and unverified system changes.
  • [COMMAND_EXECUTION]: The skill uses external command-line interfaces (codex, agy) to perform its core logic.
  • Evidence: Both SKILL.md and reference/tri-engine-failure.md describe the dependency on these CLI tools for the parallel failure mode enumeration workflow.
  • [INDIRECT_PROMPT_INJECTION]: The skill functions as a vector for indirect prompt injection by ingesting untrusted artifacts and generating actionable instructions for other agents.
  • Ingestion points: According to SKILL.md, the skill ingests data from multiple sources including Scribe[unified] specs, Spark feature proposals, and Magi strategy documents.
  • Boundary markers: The skill does not implement boundary markers or instructions to disregard potential malicious prompts within the processed data.
  • Capability inventory: The agent has the ability to execute shell commands and generate "Fix Prompts" for other agents (Builder, Beacon, Triage, etc.), creating a chain where a malicious instruction in a spec could result in unauthorized actions by a downstream agent.
  • Sanitization: No sanitization process is described for the input data before it is incorporated into prompts for other agents.
  • Evidence: The fix-prompt-generation feature described in SKILL.md and reference/fix-prompt-generation.md automates the creation of prompts for other agents based on external documentation, without providing verification layers to prevent the propagation of malicious instructions.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — omen