eva-new-user

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains instructions to scan the current environment's installation directory or repository for eva*/SKILL.md files to identify available features. This discovery process is restricted to the local environment and intended for user guidance.
  • [SAFE]: The skill processes user-supplied drafts and topics for instructional exercises. Analysis of Indirect Prompt Injection surface: 1. Ingestion points: User-provided text for tutorial prompts. 2. Boundary markers: Absent. 3. Capability inventory: Local file system discovery and context routing between skills. 4. Sanitization: Absent. This represents a low-risk vulnerability surface typical of interactive agents.
  • [SAFE]: The skill utilizes local shared reference files (../eva-shared/) for navigation logic, which is an expected architecture for a modular system developed by the same author. All referenced skills (e.g., eva-think, eva-create) are recognized as internal vendor resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 08:54 AM
Security Audit — agent-trust-hub — eva-new-user