debugging-livekit-agents
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the 'lk' CLI tool to manage local agent processes and simulate user turns through subcommands like 'start', 'say', and 'stop'. These operations are local and limited to the developer's environment for debugging purposes.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided strings during the debugging process, which introduces a surface for indirect prompt injection to the agent under test. 1. Ingestion points: The 'lk agent debugger say' command in SKILL.md accepts user-supplied text strings. 2. Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the test strings. 3. Capability inventory: The skill employs command execution via the 'lk' CLI tool. 4. Sanitization: There is no evidence of input sanitization or validation before passing user text to the debugging command.
Audit Metadata