skills/lulu-eva/eva-skill/eva-brief/Gen Agent Trust Hub

eva-brief

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external materials such as brand briefs, product requirements, and draft copies provided by the user. This creates a surface for indirect prompt injection where an attacker might include hidden instructions within these materials. However, the skill explicitly includes a safety mechanism by referencing ../eva-shared/references/shared/06_external-material-safety_外部材料安全边界.md, which is intended to define safety boundaries and prevent external materials from overriding agent instructions.
  • [SAFE]: The skill references various local files using relative paths (e.g., ../eva-shared/). This behavior is documented as a requirement for the skill to function alongside its companion 'eva-shared' resource and does not involve unauthorized system access or sensitive data exfiltration.
  • [SAFE]: No network operations, external downloads, or third-party package dependencies were found in the analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 11:32 PM
Security Audit — agent-trust-hub — eva-brief