eve-deploy-debugging

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill includes instructions for commands that retrieve environment metadata and logs, specifically eve secrets list and eve job runner-logs. These tools provide visibility into platform configuration and application output which are necessary for debugging but represent a data exposure surface.
  • [INDIRECT_PROMPT_INJECTION]: The workflows described involve the agent processing potentially untrusted data sources.
  • Ingestion points: Repository content located in the directory specified by --repo-dir, user-provided deployment pipeline inputs via --inputs, and live log output from the eve job follow command.
  • Boundary markers: There are no explicit instructions for the agent to use delimiters or ignore embedded directives when parsing logs or repository files.
  • Capability inventory: The skill enables the agent to perform deployment actions, environment configuration, and secret management via the eve CLI toolset.
  • Sanitization: The instructions do not include steps for sanitizing or validating inputs from external repositories or pipeline configurations before they are processed by the platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:51 AM
Security Audit — agent-trust-hub — eve-deploy-debugging