argent-qa-flows

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use specific command-line tools to manage the testing environment and execute generated flows.
  • The command stop-all-simulator-servers --devices <device> is used to recycle simulator services for specific devices to ensure deterministic testing.
  • The tools flow-execute and argent flow run are used to run the authored YAML flows and verify their success.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process potentially untrusted data from external sources such as tickets or test cases.
  • Ingestion points: Test cases, tickets, and acceptance criteria provided by the user in the prompt (as described in the skill's purpose for argent-qa-flows).
  • Boundary markers: The instructions do not specify the use of delimiters or specific warnings to ignore embedded instructions within the user-provided test descriptions.
  • Capability inventory: The agent has the ability to execute simulator management commands and test runners (stop-all-simulator-servers, flow-execute, argent flow run).
  • Sanitization: There are no explicit instructions to sanitize or escape the input data before translating it into the test flow YAML.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 05:31 PM
Security Audit — agent-trust-hub — argent-qa-flows