Agentv governance
Author, edit, and lint `governance:` blocks in `*.eval.yaml` files. Use when creating or updating evaluation suites that carry AI-governance metadata (OWASP LLM Top 10, OWASP Agentic Top 10, MITRE ATLAS, EU AI Act, ISO 42001). Also use non-interactively (e.g., from a GitHub Action) to lint changed eval files and report violations against the rules in `references/lint-rules.md`. Do NOT use for running evals or benchmarking — that belongs to agentv-bench.From its SKILL.md
npx -y skills add EntityProcess/agentv --skill agentv-governanceAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- 15 stars15 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
- runs commandsInstructs the agent to run 2 commands, including `agentv skills get agentv-governance --ref lint-rules` and 1 more.
SKILL.md
3.1 KB, 705 tokens by cl100k_base, as published. Nobody here has run it
AgentV Compliance Skill
Teaches AI agents how to author syntactically correct governance: blocks in AgentV
eval files, and how to lint them against known vocabulary rules.
Dual mode
Authoring (interactive): When a human or AI agent is editing a *.eval.yaml file
that contains or should contain a governance: block, this skill provides vocabulary,
valid values, and example shapes. Load it alongside agentv-eval-writer when building
red-team or compliance suites.
Linting (non-interactive / CI): When invoked from a GitHub Action (see
examples/governance/compliance-lint/), this skill lints each changed *.eval.yaml file
against the rules in references/lint-rules.md and returns a structured JSON report.
The expected output format is:
{
"pass": true,
"violations": [
{
"rule": "known_key",
"key": "risk_level",
"value": "high",
"message": "Unknown governance key 'risk_level'. Did you mean 'risk_tier'?",
"suggestion": "Replace 'risk_level' with 'risk_tier'."
}
]
}
pass is true when violations is empty.
Reference files
| File | Purpose |
|---|---|
references/governance-yaml-shape.md | YAML shape, merge semantics, worked examples |
references/lint-rules.md | Machine-readable rules applied during lint |
references/owasp-llm-top-10-2025.md | LLM01–LLM10 canonical IDs and descriptions |
references/owasp-agentic-top-10-2025.md | T01–T10 agentic-AI categories |
references/mitre-atlas.md | Common AML.Txxxx technique IDs |
references/eu-ai-act-risk-tiers.md | Four risk tiers + article references |
references/iso-42001-controls.md | Curated ISO/IEC 42001:2023 controls for AI eval |
Quick authoring guide
- Check which risks this eval exercises using the reference files above.
- Pick IDs from the relevant frameworks (
owasp_llm_top_10_2025,mitre_atlas, etc.). - Set
risk_tierusing EU AI Act vocabulary (prohibited | high | limited | minimal). - Add
controlsas<FRAMEWORK>-<VERSION>:<ID>strings (e.g.EU-AI-ACT-2024:Art.55). - Run the lint rules from
references/lint-rules.mdagainst your block before committing. - See
references/governance-yaml-shape.mdfor complete examples copied from real suites.
Accessing reference files
To load a specific reference without pulling the entire skill into context:
agentv skills get agentv-governance --ref lint-rules
Or resolve the skill directory and read files directly:
cat $(agentv skills path agentv-governance)/references/lint-rules.md
Use --full to retrieve every framework reference in one shot.
What ships with it: 7 files
18.3 KB alongside SKILL.md
references/
- eu-ai-act-risk-tiers.md2.2 KB
- governance-yaml-shape.md3.8 KB
- iso-42001-controls.md2.4 KB
- lint-rules.md4.6 KB
- mitre-atlas.md1.5 KB
- owasp-agentic-top-10-2025.md2.1 KB
- owasp-llm-top-10-2025.md1.7 KB