eve-job-debugging
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The documentation indicates that carryover context (including learnings, decisions, runbooks, context, conventions, and user data) written to agent memory is persisted and available to subsequent attempts of the same agent. This creates a potential vector for indirect prompt injection if data from one attempt is used to influence or override instructions in future attempts.
- Ingestion points: Agent memory fields mentioned in the 'Multi-Attempt Agent Runs' section of SKILL.md.
- Boundary markers: None identified in the provided instructions; no specific guidance on delimiting or ignoring embedded instructions within the persisted memory is provided.
- Capability inventory: The skill uses the 'eve' CLI for streaming logs, waiting on completion, retrieving results, diagnosing errors, and listing dependencies.
- Sanitization: There is no mention of sanitization, validation, or filtering of the carryover context before it is re-interpolated into the agent's context.
Audit Metadata