ov-kanban
Fail
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: HIGHPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The
references/loop.shscript contains a default execution command for the agent (OV_KANBAN_CMD) that explicitly uses the--dangerously-bypass-approvals-and-sandboxflag. This configuration intentionally removes security constraints and manual approval steps, potentially allowing the agent to execute high-risk commands on the host system without oversight. - [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves agents reading and acting upon instructions from shared markdown files stored in OpenViking, creating a significant attack surface for indirect injection.
- Ingestion points: Agents retrieve task data from files located at
viking://agent/kanban/<board>/<id>.mdusing theov readcommand. - Boundary markers: The protocol lacks any boundary markers or instructions to treat the ingested data as untrusted; instead,
SKILL.mddescribes theContextandDecisionssections as the 'contract' for the work. - Capability inventory: The skill uses the
ovCLI for file and directory operations and provides aloop.shscript for automated task execution, which can be leveraged to execute injected instructions. - Sanitization: There is no evidence of sanitization, filtering, or validation performed on the task file content before it is processed as instructional input.
- [DYNAMIC_EXECUTION]: The
references/loop.shscript usesevalto execute a command string (OV_KANBAN_CMD) constructed at runtime with a prompt file path. This dynamic assembly of shell commands increases the risk of command injection. - [COMMAND_EXECUTION]: The skill heavily relies on the
ovCLI and custom bash scripts to manage state and drive the agent's logic loop. Instructions inSKILL.mddirect the agent to 'do the first unchecked item in Next', which leads to the execution of arbitrary actions defined in the shared task files.
Recommendations
- AI detected serious security threats
Audit Metadata