eve-skill-distillation
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a process for capturing patterns from external data sources to generate new persistent instructions.
- Ingestion points: Step 2 of the workflow in
SKILL.mdspecifies that workers should read 'existing skills, reference docs, conversation history' to perform distillation. - Boundary markers: The instructions lack explicit boundary markers or directives for the agent to disregard instructions embedded within the ingested source material during the distillation process.
- Capability inventory: The workflow involves writing files to the local file system (creating/updating
SKILL.mdfiles) and spawning sub-agents (workers) to execute tasks. - Sanitization: No sanitization, filtering, or validation steps are present to ensure that malicious prompts in the conversation history or reference documents are not 'distilled' into the generated skill files.
Audit Metadata