openviking-skills

Warn

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill facilitates the installation of code from external Git repositories via the add_skill(path=...) tool and from remote database paths (viking:// URIs). This allows the agent to fetch and potentially execute logic from third-party sources.
  • [COMMAND_EXECUTION]: The instructions direct the agent to modify file permissions (chmod +x) on downloaded scripts and execute them from a local directory (~/.openviking/skills/). It also utilizes external CLI tools like ov, zip, and curl for file management and uploads.
  • [DYNAMIC_EXECUTION]: The skill implements a runtime execution pattern where remote files are retrieved, written to the local filesystem, and then executed as executable scripts. This bypasses static analysis of the skill's own code.
  • [DATA_EXFILTRATION]: The skill scans local directories used by other AI agents (e.g., ~/.claude/skills, ~/.cursor/skills) for migration. While it advises checking for credentials, the ability to read and upload local configuration files to a shared database (viking://agent/skills) or a remote upload URL via curl creates a significant exposure risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and follow instructions from third-party SKILL.md files, making it susceptible to injection attacks embedded in shared or downloaded skills.
  • Ingestion points: External Git repositories, viking:// database paths, and local skill folders.
  • Boundary markers: The skill notes that ingested content does not outrank the user, but does not specify technical delimiters or strict schema validation for the ingested instructions.
  • Capability inventory: Includes file writes, chmod operations, script execution, and network uploads.
  • Sanitization: Instructs the agent to manually inspect files for credentials and tokens, but lacks automated sanitization or sandboxing of the ingested prompts.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 2, 2026, 09:47 PM
Security Audit — agent-trust-hub — openviking-skills