autopilot
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill manages implementation tasks through CLI tools including
omc teamand the well-knowncursor-agent. It also utilizes the Linuxflockutility for kernel-level advisory locking of state files. - [DYNAMIC_EXECUTION]: As its primary intended function, the skill autonomously generates, builds, and tests code based on user-provided ideas. This execution is scoped within a structured multi-phase lifecycle.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user ideas to drive the development process. It implements robust mitigations through a mandatory multi-perspective validation phase (Phase 4), which includes a dedicated
security-reviewersubagent to verify the generated code for vulnerabilities. - Ingestion points: User-supplied product ideas or task descriptions provided as arguments to the skill.
- Boundary markers: Utilizes session-scoped state and transcript evidence boundaries to isolate execution contexts.
- Capability inventory: Spawns specialized subagents (architect, security-reviewer, code-reviewer), writes files to the
.omc/directory, and executes code via the team runtime. - Sanitization: Employs mandatory functional, security, and quality reviews that must all reach consensus before completion.
- [SAFE]: The skill accesses
~/.config/claude-omc/config.jsoncsolely to retrieve its own configuration settings and project-specific overrides, following standard user-level application practices.
Audit Metadata