team
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill orchestrates tasks by spawning and managing worker processes within
tmuxpanes and interacting with theomxCLI tool for state management. - [INDIRECT_PROMPT_INJECTION]: The orchestration model involves multiple agents processing shared task data and communicating via mailboxes, which creates a surface for indirect instructions.
- Ingestion points: The skill ingests user-supplied task strings and reads context from markdown files located in
.omx/context/. - Boundary markers: Commands are structured using JSON inputs (e.g.,
omx team api --input '...'), which provides a clear boundary between the tool arguments and the data payload. - Capability inventory: The skill possesses the ability to spawn long-running shell sessions via
tmux, execute CLI commands, and perform file operations within the.omx/state directory. - Sanitization: No explicit sanitization or filtering of the messages exchanged through the agent mailbox system is described in the operational instructions.
Audit Metadata