eas-update-insights
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on
eas-clito perform update management tasks, executing commands such aseas update:listandeas update:insightswithin the user's environment.\n- [PROMPT_INJECTION]: The skill ingests data from external sources, specifically update metadata retrieved througheas-cli. This creates an indirect prompt injection surface where external content is processed by the agent. Ingestion points: Update messages fetched viaeas update:list. Boundary markers: None identified. Capability inventory: Shell command execution viaeas-cli. Sanitization: None specified for the ingested metadata.\n- [SAFE]: The skill uses established tools from Expo, a well-known service, and its operations align with standard developer workflows for monitoring application health without signs of malicious intent or obfuscation.
Audit Metadata