Omm ViewSAFE
Turn complex codebases into clear, navigable architecture diagrams with Claude Code.
Overview
Turn complex codebases into clear, navigable architecture diagrams with Claude Code.
a306c32c4012OBSERVED · 2026-10-09What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: omm-view description: Start the omm web viewer to explore architecture diagrams in the browser. Use when the user says "omm view", "open viewer", "show diagrams", "view architecture", or "open architecture". argument-hint: "[--port <port>]" --- # omm-view — Architecture Viewer ## Purpose Launch the interactive web viewer so the user can explore `.omm/` architecture diagrams in their browser. ## Prerequisites Ensure the `omm` CLI is available: ```bash command -v omm || npm install -g oh-my-mermaid ``` If the install command fails (permission denied), tell the user: "Please run `npm install -g oh-my-mermaid` in your terminal, then try again." ## Steps ### Step 1: Verify .omm/ exists ```bash omm list ``` If no classes found, tell the user: "No architecture docs found. Run `/omm-scan` first to generate them." Then stop. ### Step 2: Start the viewer ```bash omm view ``` If the user specified a port: ```bash omm view --port <port> ``` ### Step 3: Report Tell the user the viewer is running and provide the URL (default: `http://localhost:3000`). The viewer auto-refreshes when `.omm/` files change. ## Rules - Always check for existing classes before starting the viewer - If no classes exist, suggest `/omm-scan` instead of starting an empty viewer - The viewer is read-only — it does not modify `.omm/` files
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
a306c32c4012full audit observations/trust-audit/skill/oh-my-mermaid__omm-view.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | a306c32c4012 | SAFE | B | 89 | first audit |
Questions
What does the Omm View skill do?
Turn complex codebases into clear, navigable architecture diagrams with Claude Code.
Is Omm View safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Omm View access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (a306c32c4012), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.