argent-tv-interact

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from target TV applications, which could contain malicious instructions aimed at the agent.
  • Ingestion points: UI element labels and tree structures retrieved via the describe tool; application console logs accessed via debugger-log-registry; network logs.
  • Boundary markers: Absent. There are no instructions for the agent to use delimiters or treat UI/log data as untrusted.
  • Capability inventory: Use of tv-remote for navigation, keyboard for typing, and debugger-evaluate for code execution.
  • Sanitization: Absent. Data from the device is used directly without validation.
  • [DYNAMIC_EXECUTION]: The skill allows the execution of arbitrary code within the target device environment.
  • Evidence: The debugger-evaluate tool enables the execution of JavaScript strings on the Vega (Fire TV) runtime. Additionally, reinstall-app allows installing .vpkg package files, which involves loading and executing third-party binaries or assets on the target device.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 07:28 AM
Security Audit — agent-trust-hub — argent-tv-interact