eve-bootstrap
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses several CLI commands for project management and authentication (e.g.,
eve auth request-access,ssh-keygen,npm install). These are part of the intended developer onboarding workflow. - [EXTERNAL_DOWNLOADS]: Installs the platform CLI tool via NPM (
@anthropic/eve-cli). Note: while the organization name '@anthropic' matches the trusted list, the skill itself refers to a vendor namespace used for technical scaffolding. No execution of untrusted remote scripts was detected. - [SAFE]: Accessing local SSH public keys (
~/.ssh/*.pub) is a documented part of the authentication challenge-response flow for this platform and does not constitute exfiltration of private keys.
Audit Metadata