eas-update-insights

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on eas-cli to perform update management tasks, executing commands such as eas update:list and eas update:insights within the user's environment.\n- [PROMPT_INJECTION]: The skill ingests data from external sources, specifically update metadata retrieved through eas-cli. This creates an indirect prompt injection surface where external content is processed by the agent. Ingestion points: Update messages fetched via eas update:list. Boundary markers: None identified. Capability inventory: Shell command execution via eas-cli. Sanitization: None specified for the ingested metadata.\n- [SAFE]: The skill uses established tools from Expo, a well-known service, and its operations align with standard developer workflows for monitoring application health without signs of malicious intent or obfuscation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 07:48 PM
Security Audit — agent-trust-hub — eas-update-insights