skills/actimi/ovok-skills/ovok/Gen Agent Trust Hub

ovok

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by instructing the agent to ingest data from external sources.\n
  • Ingestion points: User repository files (e.g., AGENTS.md), external documentation from docs.ovok.com (including llms.txt files), and the Ontoly Software Graph.\n
  • Boundary markers: There are no explicit instructions for the agent to distinguish between platform documentation and potential malicious instructions embedded within that documentation.\n
  • Capability inventory: The skill guides the agent to interact with Ovok APIs (GET, PUT, PATCH), use SDKs, and inspect/modify local source code.\n
  • Sanitization: The instructions do not define specific sanitization or validation protocols for data retrieved from external sources.\n- [EXTERNAL_DOWNLOADS]: The skill fetches documentation, configuration, and structural maps from official vendor domains such as docs.ovok.com and ovok.com. These operations are limited to project documentation and development tools related to the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:47 PM