eva-learn
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes external materials, which introduces an indirect prompt injection surface.
- Ingestion points: User-provided files, pasted text, and screenshots are ingested into the learning context.
- Boundary markers: The skill explicitly references
../eva-shared/references/shared/06_external-material-safety_外部材料安全边界.mdto define safety boundaries for external content. - Capability inventory: Capabilities include reading shared configurations and writing study logs/indexes within user-specified directories (e.g.,
~/Documents/eva-learn/). - Sanitization: External content handling is governed by a referenced safety preloading and validation protocol.
- [SAFE]: No obfuscation, unauthorized remote execution, or hardcoded secrets were detected. All external dependencies are restricted to the author's own shared resources and local file operations are scoped to user documents.
Audit Metadata