eve-orchestration

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The orchestration pattern involves parent agents generating child job descriptions that may incorporate untrusted external data, which could contain hidden instructions targeting child agents.\n
  • Ingestion points: Parent agents read and synthesize summaries and work products from child jobs as described in the orchestration flow in SKILL.md.\n
  • Boundary markers: The child job description template uses structural headers (Scope, Context, Deliverable) but lacks explicit instructions for child agents to ignore instructions embedded within the ingested context.\n
  • Capability inventory: The skill leverages the eve CLI for job management and execution within a bash environment, which provides significant capability to any successfully injected instructions.\n
  • Sanitization: The instructions do not prescribe sanitization or escaping of data before it is passed between jobs or interpolated into job descriptions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:51 AM
Security Audit — agent-trust-hub — eve-orchestration