eva-brief
Pass
Audited by Gen Agent Trust Hub on Jul 19, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external materials such as brand briefs, product requirements, and draft copies provided by the user. This creates a surface for indirect prompt injection where an attacker might include hidden instructions within these materials. However, the skill explicitly includes a safety mechanism by referencing
../eva-shared/references/shared/06_external-material-safety_外部材料安全边界.md, which is intended to define safety boundaries and prevent external materials from overriding agent instructions. - [SAFE]: The skill references various local files using relative paths (e.g.,
../eva-shared/). This behavior is documented as a requirement for the skill to function alongside its companion 'eva-shared' resource and does not involve unauthorized system access or sensitive data exfiltration. - [SAFE]: No network operations, external downloads, or third-party package dependencies were found in the analyzed files.
Audit Metadata