skills/yeachan-heo/oh-my-codex/worker/Gen Agent Trust Hub

worker

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to read and execute instructions retrieved from external task and mailbox files, creating a surface for potential instruction injection if these files are compromised or contain untrusted content.
  • Ingestion points: The agent reads task assignments from inbox.md and detailed task data from task-<id>.json files located in the <team_state_root>.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the content of these files as data rather than instructions.
  • Capability inventory: The skill possesses the ability to execute shell commands via the omx CLI tool and perform filesystem writes to state and status files.
  • Sanitization: The instructions do not specify any validation or sanitization logic for the content parsed from the inbox or task JSON files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:53 PM
Security Audit — agent-trust-hub — worker