jev-integrate

Fail

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill instructs the agent to retrieve sensitive credentials from the system keychain using the command 'security find-generic-password -s typesafe-api-key -w'. These credentials are then transmitted to the external domain 'api.typesafe.ai' via a 'curl' POST request. The domain 'typesafe.ai' is not recognized as a trusted or whitelisted service, posing a high risk of credential exfiltration.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill recommends installing the 'von-sdk' Python package via 'pip' without specifying a version or verifying the source. Installing unpinned packages from public registries can lead to supply chain vulnerabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data ('state') through various models without defining boundary markers or sanitization procedures. * Ingestion points: The 'state' parameter is passed into network requests, Cloudflare Workers AI calls, and the Von SDK. * Boundary markers: Absent; there are no instructions to delimit or ignore embedded instructions within the ingested data. * Capability inventory: The skill has access to network tools ('curl'), credential retrieval tools ('security'), and package managers ('pip'). * Sanitization: Absent; the skill does not specify any validation or escaping for the processed data.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 24, 2026, 12:51 AM
Security Audit — agent-trust-hub — jev-integrate