jev-eval
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/sweep.pyexecutes the macOSsecurityutility viasubprocess.runto retrieve thetypesafe-api-keyfrom the system keychain for API authentication. This is a documented administrative action for the skill. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data which is then used to construct prompts for an LLM, creating a vulnerability surface.
- Ingestion points: Records are loaded from
labelled.jsonand criteria configurations fromconfigs.jsoninscripts/sweep.py. - Boundary markers: The script does not implement specific delimiters or 'ignore' instructions for the ingested data.
- Capability inventory: Performs authenticated POST requests to
https://api.typesafe.ai/v1/systemoneusingurllib.request. - Sanitization: The script does not sanitize the input strings before sending them to the remote API.
Audit Metadata