eve-skill-distillation

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for capturing patterns from external data sources to generate new persistent instructions.
  • Ingestion points: Step 2 of the workflow in SKILL.md specifies that workers should read 'existing skills, reference docs, conversation history' to perform distillation.
  • Boundary markers: The instructions lack explicit boundary markers or directives for the agent to disregard instructions embedded within the ingested source material during the distillation process.
  • Capability inventory: The workflow involves writing files to the local file system (creating/updating SKILL.md files) and spawning sub-agents (workers) to execute tasks.
  • Sanitization: No sanitization, filtering, or validation steps are present to ensure that malicious prompts in the conversation history or reference documents are not 'distilled' into the generated skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:50 AM
Security Audit — agent-trust-hub — eve-skill-distillation