eve-troubleshooting

Pass

Audited by Gen Agent Trust Hub on Feb 19, 2026

Risk Level: SAFE
Full Analysis
  • [Data Exposure] (SAFE): The skill mentions sensitive paths like .eve/dev-secrets.yaml and commands like eve secrets set. However, it does not include hardcoded credentials, nor does it contain logic to exfiltrate these files or values to external servers.
  • [Prompt Injection] (SAFE): No instructions were found that attempt to override the AI agent's core safety guidelines or manipulate its behavioral constraints.
  • [Remote Code Execution] (SAFE): The skill strictly uses the eve CLI for troubleshooting. There are no patterns involving the download and execution of remote scripts (e.g., piping curl to bash).
  • [Indirect Prompt Injection] (SAFE): While the skill involves reading CLI output and logs (which could theoretically contain untrusted data), it does so within its primary troubleshooting scope and provides no specific exploit vectors or downstream automated actions based on that data.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 19, 2026, 03:49 PM