eve-fullstack-app-design

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references platform-specific resources such as the eve-horizon/migrate Docker image hosted on AWS Public ECR and several Node.js packages within the @eve-horizon scope. These are legitimate dependencies provided by the platform vendor for its development ecosystem.
  • [COMMAND_EXECUTION]: Technical instructions provide examples of using the eve CLI for infrastructure management, secret configuration, and deployment monitoring. These commands are contextual to the platform's intended use and do not facilitate unauthorized actions.
  • [CREDENTIALS_UNSAFE]: The skill explicitly advises against hardcoding sensitive data, instead promoting the use of built-in secret management features and auto-injected tokens (EVE_SERVICE_TOKEN, EVE_JOB_TOKEN). It also provides a robust pattern for multi-tenant database security using PostgreSQL Row-Level Security (RLS).
  • [DATA_EXFILTRATION]: No suspicious data transfer behaviors were identified. Network operations mentioned (e.g., curl or fetch in Docker health checks and smoke tests) are standard operational practices for verifying service availability.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:50 AM
Security Audit — agent-trust-hub — eve-fullstack-app-design