eve-fullstack-app-design
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references platform-specific resources such as the
eve-horizon/migrateDocker image hosted on AWS Public ECR and several Node.js packages within the@eve-horizonscope. These are legitimate dependencies provided by the platform vendor for its development ecosystem. - [COMMAND_EXECUTION]: Technical instructions provide examples of using the
eveCLI for infrastructure management, secret configuration, and deployment monitoring. These commands are contextual to the platform's intended use and do not facilitate unauthorized actions. - [CREDENTIALS_UNSAFE]: The skill explicitly advises against hardcoding sensitive data, instead promoting the use of built-in secret management features and auto-injected tokens (
EVE_SERVICE_TOKEN,EVE_JOB_TOKEN). It also provides a robust pattern for multi-tenant database security using PostgreSQL Row-Level Security (RLS). - [DATA_EXFILTRATION]: No suspicious data transfer behaviors were identified. Network operations mentioned (e.g.,
curlorfetchin Docker health checks and smoke tests) are standard operational practices for verifying service availability.
Audit Metadata