ov-skills
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill enables fetching and installing code from external sources, including Git repositories and GitHub tree URLs. Examples provided in the documentation reference the official anthropics/skills repository.
- [COMMAND_EXECUTION]: The skill uses the ov skills CLI to perform system-level management of agent capabilities, including adding, listing, and removing skills.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (URLs and skill content) which could serve as a vector for indirect prompt injection. * Ingestion points: User-provided URLs and raw SKILL.md content processed by ov skills add in SKILL.md and docs/source-types.md. * Boundary markers: The skill includes instructions to verify untrusted URLs and mandates user confirmation for destructive actions like remove --all. * Capability inventory: The skill can download and install new code/instructions and modify the agent's available skills using the ov CLI. * Sanitization: Relies on the agent to verify source trustworthiness as directed by the workflow instructions.
Audit Metadata