eve-agent-optimisation

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze agent execution logs, which are external data sources that may contain untrusted input.
  • Ingestion points: In SKILL.md, the 'Diagnostic Workflow' section instructs the agent to read execution records using eve job diagnose and eve job logs.
  • Boundary markers: No specific boundary markers or delimiters are defined to separate untrusted log content from the agent's internal instructions.
  • Capability inventory: The agent is tasked with recommending changes to critical configurations including SKILL.md files, model selection, and permission policies like yolo mode.
  • Sanitization: The instructions do not include any steps for sanitizing or validating the content of the logs before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:50 AM
Security Audit — agent-trust-hub — eve-agent-optimisation