eve-troubleshooting
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a variety of diagnostic and management commands using the
evecommand-line interface. These tools are used for project synchronization, job diagnostics, and system health checks, which are appropriate for the intended troubleshooting use case.\n- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to execute commands using user-supplied parameters like job IDs, project names, and environment identifiers. This creates a surface where malformed input could potentially influence CLI behavior.\n - Ingestion points: Parameters like
<job-id>,<project>,<env>, and<hostname>inSKILL.md.\n - Boundary markers: None identified; instructions do not explicitly warn the agent to sanitize or ignore instructions embedded in these identifiers.\n
- Capability inventory: The
eveCLI provides capabilities for secret management (secrets set), job control (job diagnose), and administrative access to email delivery logs (admin email bounces).\n - Sanitization: No specific input validation or escaping mechanisms are described for the parameter values.
Audit Metadata