skills/yeachan-heo/oh-my-codex/cancel/Gen Agent Trust Hub

cancel

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands using the omx utility, such as omx state list-active, omx team status, and omx state clear. These commands are used to inspect and modify the state of the local operational environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from command-line outputs, creating a surface for indirect prompt injection if the state data contains malicious instructions.
  • Ingestion points: Data is read from the JSON output of omx state list-active and omx team status.
  • Boundary markers: The instructions rely on JSON structure but do not explicitly warn the agent to ignore instructions embedded within the data values.
  • Capability inventory: The skill can execute various omx subcommands that mutate the system state.
  • Sanitization: The skill mandates argument validation and confirmation of session evidence before performing cleanup actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:53 PM
Security Audit — agent-trust-hub — cancel