ov-resources

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the use of the ov CLI utility for resource management, filesystem navigation, and content modification.
  • [DATA_EXFILTRATION]: The ov backup and ov export commands allow for the aggregation and extraction of sensitive system state, user data, and session context from the viking:// namespace into portable .ovpack files.
  • [PROMPT_INJECTION]: The skill instructions allow the agent to ingest and process data from untrusted external sources, creating a risk for indirect prompt injection. 1. Ingestion points: ov add-resource accepts input from URLs, local files, and remote Git repositories. 2. Boundary markers: The skill does not provide instructions to isolate external content or treat it as untrusted data. 3. Capability inventory: The agent has access to powerful operations such as recursive deletion (ov rm --recursive) and data export. 4. Sanitization: There is no requirement for content validation or instruction filtering before the data is read by the agent.
  • [PERSISTENCE_MECHANISMS]: The ov task watch functionality allows for the creation of scheduled background tasks that periodically re-execute resource ingestion, effectively maintaining operations across agent sessions.
  • [EXTERNAL_DOWNLOADS]: The ov add-resource command enables downloading content from remote locations and cloning Git repositories, including those from the vendor's own namespace.
  • [PRIVILEGE_ESCALATION]: Documentation indicates that administrative operations such as backup, restore, export, and import require ROOT or ADMIN level permissions within the environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 08:49 PM
Security Audit — agent-trust-hub — ov-resources