fine-tuning-openvla-oft
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to clone and install third-party research repositories, specifically
github.com/moojink/openvla-oftandgithub.com/Lifelong-Robot-Learning/LIBERO, which are required to access the training and evaluation scripts. - [INDIRECT_PROMPT_INJECTION]: The skill implements Vision-Language-Action (VLA) models that use language conditioning to generate robot actions, creating a surface for indirect prompt injection via untrusted task instructions.
- Ingestion points: Language-based task descriptions processed during inference in
experiments/robot/libero/run_libero_eval.pyandexperiments/robot/aloha/run_aloha_eval.py. - Boundary markers: No explicit boundary markers or instruction-guarding delimiters are identified in the workflow documentation.
- Capability inventory: The skill includes model training (
vla-scripts/finetune.py), deployment of an inference server (vla-scripts/deploy.py), and real-world robot control execution (experiments/robot/aloha/run_aloha_eval.py). - Sanitization: There is no mention of input sanitization or validation for the natural language task instructions.
- [COMMAND_EXECUTION]: The workflow requires the execution of shell commands for environment setup and model training, including
pip install,conda create, andtorchrunfor distributed training.
Audit Metadata