writing-livekit-scenarios
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
lk agent simulatecommand, a standard utility in the LiveKit ecosystem for generating and executing agent simulations. - [INDIRECT_PROMPT_INJECTION]: The skill describes a testing framework where agents ingest 'userdata' from scenario files. 1. Ingestion points: The agent reads 'userdata' mapping from scenario files via the job context at runtime. 2. Boundary markers: The skill recommends structured templates (e.g., PERSONA, FACTS, DO) to steer the simulated user model. 3. Capability inventory: The framework supports tool mocking, state seeding, and final state grading via callbacks. 4. Sanitization: The skill promotes deterministic end-state checks and specific persona definitions to limit the model's range of behavior.
- [SAFE]: No malicious patterns such as obfuscation, credential exfiltration, or unauthorized persistence mechanisms were detected. All external references and tools are consistent with the LiveKit platform, including the documented behavior of uploading code to LiveKit Cloud for scenario generation.
Audit Metadata