eve-plan-implementation
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill defines a workflow where the agent constructs shell commands for the
eveCLI using placeholders like<objective>,<result>, and<anything the worker needs>derived from external plan documents. If these documents contain shell metacharacters, it could lead to command injection when the commands are executed. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data from external sources, creating an attack surface for indirect prompt injection.
- Ingestion points: The skill reads plan documents and
AGENTS.md(found inSKILL.md) to extract project structure, phases, and task descriptions. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when processing the content of plan documents.
- Capability inventory: The skill utilizes the
eveCLI for job creation, management, and dependency wiring, and includes a template for Git controls (branching, committing, pushing). - Sanitization: There is no mention of sanitizing or validating the text extracted from plan documents before it is interpolated into shell commands or job descriptions.
Audit Metadata