omc-setup

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill frequently executes shell commands to manage the environment and install tools.
  • Executes bundled bash and Node.js scripts (e.g., setup-claude-md.sh, repair-plugin-cache.mjs) to coordinate the installation.
  • Uses npm install -g oh-my-claude-sisyphus to install the project's global CLI tool.
  • Uses the gh CLI to interact with the GitHub API for starring the repository, which is performed only after explicit user confirmation.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with external registries to manage the lifecycle of its components.
  • Performs a version check against the npm registry using npm view.
  • Downloads and installs the CLI package from the public npm registry.
  • [PERSISTENCE]: The skill's primary function involves modifying the agent's long-term configuration files to establish its operating environment.
  • Updates CLAUDE.md (both local and global) to inject agent instructions and tiering logic.
  • Modifies ~/.claude/settings.json to enable experimental features like agent teams and the HUD status bar.
  • Manages .omc-config.json to persist user preferences across sessions.
  • [INDIRECT_PROMPT_INJECTION]: The skill populates the agent's context with persistent rules and instructions.
  • Ingestion points: The setup process reads and modifies settings.json and .omc-config.json.
  • Boundary markers: Uses specific markers within CLAUDE.md to delimit OMC-managed configuration blocks.
  • Capability inventory: The setup process has access to file system writes, package installation, and network APIs via system tools.
  • Sanitization: Employs jq for structural JSON merging to ensure configuration integrity and prevent malformed data injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 08:41 PM
Security Audit — agent-trust-hub — omc-setup