eve-deploy-debugging
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill includes instructions for commands that retrieve environment metadata and logs, specifically
eve secrets listandeve job runner-logs. These tools provide visibility into platform configuration and application output which are necessary for debugging but represent a data exposure surface. - [INDIRECT_PROMPT_INJECTION]: The workflows described involve the agent processing potentially untrusted data sources.
- Ingestion points: Repository content located in the directory specified by
--repo-dir, user-provided deployment pipeline inputs via--inputs, and live log output from theeve job followcommand. - Boundary markers: There are no explicit instructions for the agent to use delimiters or ignore embedded directives when parsing logs or repository files.
- Capability inventory: The skill enables the agent to perform deployment actions, environment configuration, and secret management via the
eveCLI toolset. - Sanitization: The instructions do not include steps for sanitizing or validating inputs from external repositories or pipeline configurations before they are processed by the platform.
Audit Metadata