eve-verification-plans
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill is fundamentally designed to execute shell commands (bash) and CLI tools (Eve CLI, curl, jq) defined within markdown test plans to verify application behavior and platform conformance. This is the intended primary purpose of a verification framework.
- [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for testing ingestion pipelines using external fixtures (CSV, PDF, Markdown). There is an inherent risk that an agent executing these plans could be influenced by malicious content embedded within these test fixtures if the agent processes the file content directly.
- Ingestion points: Fixture files defined in
templates/upload-ingest-test-plan.mdand generated via patterns inreferences/fixture-patterns.md. - Boundary markers: The framework utilizes structured markdown sections for setup, phases, and assertions, providing clear logical boundaries for the agent.
- Capability inventory: The skill utilizes shell execution, network operations via
curl, and browser automation viaagent-browserorPlaywright MCP. - Sanitization: No explicit sanitization of fixture content is performed by the skill; it assumes the author provides deterministic and safe test data.
- [DYNAMIC_EXECUTION]: The skill generates test fixtures at runtime using Python one-liners (
python3 -c) and bash heredocs. This is a standard practice for creating isolated, reproducible test environments. - [EXTERNAL_DOWNLOADS]: The documentation suggests the use of common third-party utilities for fixture generation, including
pandoc,reportlab,Pillow, andImageMagick. These are well-known tools in the developer ecosystem.
Audit Metadata