ov-resources
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the use of the
ovCLI utility for resource management, filesystem navigation, and content modification. - [DATA_EXFILTRATION]: The
ov backupandov exportcommands allow for the aggregation and extraction of sensitive system state, user data, and session context from theviking://namespace into portable.ovpackfiles. - [PROMPT_INJECTION]: The skill instructions allow the agent to ingest and process data from untrusted external sources, creating a risk for indirect prompt injection. 1. Ingestion points:
ov add-resourceaccepts input from URLs, local files, and remote Git repositories. 2. Boundary markers: The skill does not provide instructions to isolate external content or treat it as untrusted data. 3. Capability inventory: The agent has access to powerful operations such as recursive deletion (ov rm --recursive) and data export. 4. Sanitization: There is no requirement for content validation or instruction filtering before the data is read by the agent. - [PERSISTENCE_MECHANISMS]: The
ov task watchfunctionality allows for the creation of scheduled background tasks that periodically re-execute resource ingestion, effectively maintaining operations across agent sessions. - [EXTERNAL_DOWNLOADS]: The
ov add-resourcecommand enables downloading content from remote locations and cloning Git repositories, including those from the vendor's own namespace. - [PRIVILEGE_ESCALATION]: Documentation indicates that administrative operations such as
backup,restore,export, andimportrequire ROOT or ADMIN level permissions within the environment.
Audit Metadata