cancel
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands using the
omxutility, such asomx state list-active,omx team status, andomx state clear. These commands are used to inspect and modify the state of the local operational environment. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from command-line outputs, creating a surface for indirect prompt injection if the state data contains malicious instructions.
- Ingestion points: Data is read from the JSON output of
omx state list-activeandomx team status. - Boundary markers: The instructions rely on JSON structure but do not explicitly warn the agent to ignore instructions embedded within the data values.
- Capability inventory: The skill can execute various
omxsubcommands that mutate the system state. - Sanitization: The skill mandates argument validation and confirmation of session evidence before performing cleanup actions.
Audit Metadata