openviking-skills
Warn
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill facilitates the installation of code from external Git repositories via the
add_skill(path=...)tool and from remote database paths (viking://URIs). This allows the agent to fetch and potentially execute logic from third-party sources. - [COMMAND_EXECUTION]: The instructions direct the agent to modify file permissions (
chmod +x) on downloaded scripts and execute them from a local directory (~/.openviking/skills/). It also utilizes external CLI tools likeov,zip, andcurlfor file management and uploads. - [DYNAMIC_EXECUTION]: The skill implements a runtime execution pattern where remote files are retrieved, written to the local filesystem, and then executed as executable scripts. This bypasses static analysis of the skill's own code.
- [DATA_EXFILTRATION]: The skill scans local directories used by other AI agents (e.g.,
~/.claude/skills,~/.cursor/skills) for migration. While it advises checking for credentials, the ability to read and upload local configuration files to a shared database (viking://agent/skills) or a remote upload URL viacurlcreates a significant exposure risk. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and follow instructions from third-party
SKILL.mdfiles, making it susceptible to injection attacks embedded in shared or downloaded skills. - Ingestion points: External Git repositories,
viking://database paths, and local skill folders. - Boundary markers: The skill notes that ingested content does not outrank the user, but does not specify technical delimiters or strict schema validation for the ingested instructions.
- Capability inventory: Includes file writes,
chmodoperations, script execution, and network uploads. - Sanitization: Instructs the agent to manually inspect files for credentials and tokens, but lacks automated sanitization or sandboxing of the ingested prompts.
Audit Metadata