omc-doctor
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands to inspect and manage the installation environment.
- Evidence includes the use of
rm -rfandrmto delete legacy directories (agents/,commands/,skills/) and hook scripts in the~/.claudedirectory during the auto-fix phase. - It uses
ls,grep, andfindto diagnose the presence of markers and legacy scripts. - [DYNAMIC_EXECUTION]: The skill uses
node -eto run inline JavaScript for advanced file system operations. - These scripts perform version comparisons using
localeCompare, handle directory traversal viareaddirSync, and perform recursive deletions of the plugin cache withrmSync. - The logic is used to calculate version drift and clean up stale cache entries.
- [EXTERNAL_DOWNLOADS]: The skill fetches updated configuration from the author's official GitHub repository.
- It uses
WebFetchto retrieve the latestCLAUDE.mdfromhttps://raw.githubusercontent.com/Yeachan-Heo/oh-my-claudecode/main/docs/CLAUDE.md. - It queries the NPM registry via
npm view oh-my-claude-sisyphus versionto check for available updates. - [INDIRECT_PROMPT_INJECTION]: The skill parses content from user-editable files to drive its diagnostic logic.
- Ingestion points: Reads content from
CLAUDE.mdand companion files likeCLAUDE-omc.md. - Boundary markers: No explicit boundary markers or 'ignore' instructions are used when reading these files.
- Capability inventory: The skill has high-authority capabilities including file deletion (
rm), remote fetching (WebFetch), and dynamic script execution (node -e). - Sanitization: The skill uses regex patterns (e.g.,
/<!--\s*OMC:VERSION:([^\s]+)\s*-->/i) to extract specific markers, which limits the risk of processing arbitrary instructions from the file body.
Audit Metadata