omni-content-builder
Pass
Audited by Gen Agent Trust Hub on Mar 10, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill performs network operations using curl to interact with the Omni Analytics REST API at omniapp.co. These operations facilitate document and dashboard management and are directed at the vendor's own infrastructure.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it retrieves and processes data from external dashboard configurations. * Ingestion points: Dashboard and query definitions are fetched from the Omni API (SKILL.md). * Boundary markers: No explicit delimiters or instructions are present to separate untrusted dashboard content from agent instructions. * Capability inventory: The skill has permissions to create, modify, move, and delete documents and dashboards via REST API calls. * Sanitization: There is no evidence of sanitization or validation of the data retrieved from the API before it enters the agent context.
Audit Metadata