fine-tuning-openvla-oft

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to clone and install third-party research repositories, specifically github.com/moojink/openvla-oft and github.com/Lifelong-Robot-Learning/LIBERO, which are required to access the training and evaluation scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements Vision-Language-Action (VLA) models that use language conditioning to generate robot actions, creating a surface for indirect prompt injection via untrusted task instructions.
  • Ingestion points: Language-based task descriptions processed during inference in experiments/robot/libero/run_libero_eval.py and experiments/robot/aloha/run_aloha_eval.py.
  • Boundary markers: No explicit boundary markers or instruction-guarding delimiters are identified in the workflow documentation.
  • Capability inventory: The skill includes model training (vla-scripts/finetune.py), deployment of an inference server (vla-scripts/deploy.py), and real-world robot control execution (experiments/robot/aloha/run_aloha_eval.py).
  • Sanitization: There is no mention of input sanitization or validation for the natural language task instructions.
  • [COMMAND_EXECUTION]: The workflow requires the execution of shell commands for environment setup and model training, including pip install, conda create, and torchrun for distributed training.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — fine-tuning-openvla-oft