ov-kanban

Fail

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The references/loop.sh script contains a default execution command for the agent (OV_KANBAN_CMD) that explicitly uses the --dangerously-bypass-approvals-and-sandbox flag. This configuration intentionally removes security constraints and manual approval steps, potentially allowing the agent to execute high-risk commands on the host system without oversight.
  • [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves agents reading and acting upon instructions from shared markdown files stored in OpenViking, creating a significant attack surface for indirect injection.
  • Ingestion points: Agents retrieve task data from files located at viking://agent/kanban/<board>/<id>.md using the ov read command.
  • Boundary markers: The protocol lacks any boundary markers or instructions to treat the ingested data as untrusted; instead, SKILL.md describes the Context and Decisions sections as the 'contract' for the work.
  • Capability inventory: The skill uses the ov CLI for file and directory operations and provides a loop.sh script for automated task execution, which can be leveraged to execute injected instructions.
  • Sanitization: There is no evidence of sanitization, filtering, or validation performed on the task file content before it is processed as instructional input.
  • [DYNAMIC_EXECUTION]: The references/loop.sh script uses eval to execute a command string (OV_KANBAN_CMD) constructed at runtime with a prompt file path. This dynamic assembly of shell commands increases the risk of command injection.
  • [COMMAND_EXECUTION]: The skill heavily relies on the ov CLI and custom bash scripts to manage state and drive the agent's logic loop. Instructions in SKILL.md direct the agent to 'do the first unchecked item in Next', which leads to the execution of arbitrary actions defined in the shared task files.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 2, 2026, 09:47 PM
Security Audit — agent-trust-hub — ov-kanban