eve-plan-implementation

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines a workflow where the agent constructs shell commands for the eve CLI using placeholders like <objective>, <result>, and <anything the worker needs> derived from external plan documents. If these documents contain shell metacharacters, it could lead to command injection when the commands are executed.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data from external sources, creating an attack surface for indirect prompt injection.
  • Ingestion points: The skill reads plan documents and AGENTS.md (found in SKILL.md) to extract project structure, phases, and task descriptions.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when processing the content of plan documents.
  • Capability inventory: The skill utilizes the eve CLI for job creation, management, and dependency wiring, and includes a template for Git controls (branching, committing, pushing).
  • Sanitization: There is no mention of sanitizing or validating the text extracted from plan documents before it is interpolated into shell commands or job descriptions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:50 AM
Security Audit — agent-trust-hub — eve-plan-implementation