eve-agent-memory
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs agents to ingest data from multiple external and shared sources, creating a surface for indirect prompt injection. \n
- Ingestion points: Agents are directed to read from the coordination inbox (stored at
.eve/coordination-inbox.md), organization documents viaeve docs read, job attachments viaeve job attachment, and the shared organization filesystem mounted at.org/. These sources may contain content controlled by other users or potentially malicious external actors. \n - Boundary markers: The instructions lack guidance on using delimiters or explicit "ignore embedded instructions" warnings when processing data retrieved from these storage primitives. \n
- Capability inventory: The skill provides the agent with capabilities to write to the filesystem, update organization documents (
eve docs write), and execute SQL commands (eve db sql), which could be leveraged to perform unauthorized actions if the agent processes malicious instructions from the memory store. \n - Sanitization: There is no mention of sanitizing, validating, or escaping content retrieved from storage before it is interpolated into the agent's reasoning or subsequent commands.
Audit Metadata