eve-verification-plans

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill is fundamentally designed to execute shell commands (bash) and CLI tools (Eve CLI, curl, jq) defined within markdown test plans to verify application behavior and platform conformance. This is the intended primary purpose of a verification framework.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for testing ingestion pipelines using external fixtures (CSV, PDF, Markdown). There is an inherent risk that an agent executing these plans could be influenced by malicious content embedded within these test fixtures if the agent processes the file content directly.
  • Ingestion points: Fixture files defined in templates/upload-ingest-test-plan.md and generated via patterns in references/fixture-patterns.md.
  • Boundary markers: The framework utilizes structured markdown sections for setup, phases, and assertions, providing clear logical boundaries for the agent.
  • Capability inventory: The skill utilizes shell execution, network operations via curl, and browser automation via agent-browser or Playwright MCP.
  • Sanitization: No explicit sanitization of fixture content is performed by the skill; it assumes the author provides deterministic and safe test data.
  • [DYNAMIC_EXECUTION]: The skill generates test fixtures at runtime using Python one-liners (python3 -c) and bash heredocs. This is a standard practice for creating isolated, reproducible test environments.
  • [EXTERNAL_DOWNLOADS]: The documentation suggests the use of common third-party utilities for fixture generation, including pandoc, reportlab, Pillow, and ImageMagick. These are well-known tools in the developer ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:50 AM
Security Audit — agent-trust-hub — eve-verification-plans