Back to skill

Security audit

Aha Claudecode Omc

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only orchestration guide for Claude Code with OMC, with disclosed delegation and confirmation rules and no hidden execution or credential collection.

Install this only if you use Claude Code with OMC and want agent orchestration help. Review the OMC dependency separately, and watch for confirmation prompts before large fan-out, worktree use, persistent/autonomous work, or any action that could change files or cost money.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file mandates a global `verbosity:low` style with hard caps on orchestration disclosures, including a maximum of three sentences per orchestration event and one-line progress updates. In an agent skill, this can suppress important security, consent, risk, and uncertainty communication, making it easier for risky actions or policy-relevant tradeoffs to be under-explained to the user.

Static analysis

No suspicious patterns detected.