ov-add-data
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands using the 'ov' CLI. The 'ov add-skill' command can be used to add new script-based capabilities to the agent's environment.\n- [EXTERNAL_DOWNLOADS]: The skill downloads data from external URLs (e.g., GitHub, Arxiv) to store in the context database.\n- [DATA_EXFILTRATION]: The skill facilitates moving data from sensitive local directories (e.g., Documents, Photos) to a persistent database. The examples use paths associated with the vendor 'volcengine'.\n- [PROMPT_INJECTION]: Surface for Indirect Prompt Injection. Ingestion points: External resources added via 'ov add-resource' and 'ov add-skill' as described in SKILL.md. Boundary markers: No instructions are provided for sanitizing or isolating imported content to prevent the agent from executing embedded instructions. Capability inventory: The skill has read/write and network capabilities via the 'ov' CLI tool. Sanitization: No content validation or sanitization process is described for imported resources.
Audit Metadata