fine-tuning-openvla-oft

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill retrieves research source code and datasets from well-known platforms including GitHub (moojink/openvla-oft, Lifelong-Robot-Learning/LIBERO) and HuggingFace. These resources are standard for the robotics and AI research community.\n- [COMMAND_EXECUTION]: The workflow involves various CLI operations for training (torchrun), server deployment (uvicorn/fastapi), and robot environment evaluation. These commands are transparent and align with the stated research objectives.\n- [REMOTE_CODE_EXECUTION]: During setup, cloned research repositories are installed in editable mode (pip install -e .), which executes project-specific installation scripts. This is standard practice for configuring development environments in machine learning.\n- [INDIRECT_PROMPT_INJECTION]: The robotics policies ingest natural language instructions to generate actions. This creates an attack surface common to all Vision-Language-Action models, but the skill adheres to established research protocols and does not introduce specific vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:07 PM
Security Audit — agent-trust-hub — fine-tuning-openvla-oft