eve-deploy-debugging

Pass

Audited by Gen Agent Trust Hub on Mar 1, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: No malicious patterns or unauthorized behaviors were detected. The skill is consistent with its stated purpose of assisting with deployment and debugging tasks.
  • [NO_CODE]: The skill consists entirely of Markdown text and does not include any scripts, binaries, or automated tools for execution.
  • [EXTERNAL_DOWNLOADS]: The skill references a staging API URL (https://api.eh1.incept5.dev) which is a trusted resource owned by the vendor 'incept5'.
  • [PROMPT_INJECTION]: The skill involves processing external data like application logs and repository content, which constitutes a potential surface for indirect prompt injection. This is a standard functional requirement for diagnostic tools.
  • Ingestion points: Application logs (eve job runner-logs) and repository files (--repo-dir .).
  • Boundary markers: Not explicitly mentioned in the instructions.
  • Capability inventory: The 'eve' CLI enables deployment and management of environments.
  • Sanitization: Data is interpreted for diagnostic results without specified sanitization steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 1, 2026, 05:20 PM