eve-agent-memory

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs agents to ingest data from multiple external and shared sources, creating a surface for indirect prompt injection. \n
  • Ingestion points: Agents are directed to read from the coordination inbox (stored at .eve/coordination-inbox.md), organization documents via eve docs read, job attachments via eve job attachment, and the shared organization filesystem mounted at .org/. These sources may contain content controlled by other users or potentially malicious external actors. \n
  • Boundary markers: The instructions lack guidance on using delimiters or explicit "ignore embedded instructions" warnings when processing data retrieved from these storage primitives. \n
  • Capability inventory: The skill provides the agent with capabilities to write to the filesystem, update organization documents (eve docs write), and execute SQL commands (eve db sql), which could be leveraged to perform unauthorized actions if the agent processes malicious instructions from the memory store. \n
  • Sanitization: There is no mention of sanitizing, validating, or escaping content retrieved from storage before it is interpolated into the agent's reasoning or subsequent commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:50 AM
Security Audit — agent-trust-hub — eve-agent-memory