skills/lulu-eva/eva-skill/eva-learn/Gen Agent Trust Hub

eva-learn

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external materials, which introduces an indirect prompt injection surface.
  • Ingestion points: User-provided files, pasted text, and screenshots are ingested into the learning context.
  • Boundary markers: The skill explicitly references ../eva-shared/references/shared/06_external-material-safety_外部材料安全边界.md to define safety boundaries for external content.
  • Capability inventory: Capabilities include reading shared configurations and writing study logs/indexes within user-specified directories (e.g., ~/Documents/eva-learn/).
  • Sanitization: External content handling is governed by a referenced safety preloading and validation protocol.
  • [SAFE]: No obfuscation, unauthorized remote execution, or hardcoded secrets were detected. All external dependencies are restricted to the author's own shared resources and local file operations are scoped to user documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 08:54 AM
Security Audit — agent-trust-hub — eva-learn