learn-about-omx
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: LOWPROMPT_INJECTIONNO_CODE
Full Analysis
- Indirect Prompt Injection (LOW): The skill processes untrusted data from local files. Ingestion points: .omx/notepad.md and .omx/project-memory.json. Boundary markers: Absent. Capability inventory: Display-only report generation. Sanitization: Absent.
- Data Exposure (INFO): Accesses session history and project context files to generate statistics, which is consistent with the stated purpose.
Audit Metadata