eve-auth-and-secrets
Pass
Audited by Gen Agent Trust Hub on Mar 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to execute a variety of
eveCLI commands to manage authentication states, project secrets, and access control policies. - [EXTERNAL_DOWNLOADS]: The instructions involve downloading and installing official Node.js packages (
@eve-horizon/authand@eve-horizon/auth-react) to enable SSO functionality in applications. - [DATA_EXFILTRATION]: The skill performs legitimate synchronization of local developer credentials to the platform. It accesses configuration files such as
~/.ssh/id_ed25519.puband token storage files like~/.codex/auth.jsonto facilitate authentication and secret management within the Eve ecosystem.
Audit Metadata