skills/stellarlinkco/myclaude/omo/Gen Agent Trust Hub

omo

Pass

Audited by Gen Agent Trust Hub on Mar 6, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection risk identified. Ingestion points: SKILL.md and references/develop.md ingest outputs from search agents. Boundary markers: Uses markdown headers ## Context Pack but lacks explicit instructions to ignore embedded commands. Capability inventory: Subprocess execution via codeagent-wrapper and file-system write/edit capabilities in implementation agents. Sanitization: Absent; external data is pasted directly into prompts.
  • [COMMAND_EXECUTION]: The skill executes shell commands using codeagent-wrapper to orchestrate agent transitions. This pattern is central to the skill's routing logic. Additionally, the README.md refers to an install.py script for setup that is not provided in the audited file list.
  • [EXTERNAL_DOWNLOADS]: The librarian agent utilizes gh repo clone to fetch external repositories for analysis. This is documented as a core research function and targets a well-known service (GitHub).
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 6, 2026, 12:56 AM