skills/vm0-ai/vm0-skills/arga-labs/Gen Agent Trust Hub

arga-labs

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests data from external Arga Labs API endpoints, which creates an indirect prompt injection surface.
  • Ingestion points: API response data fetched from URLs defined in documentation.
  • Boundary markers: No delimiting instructions are provided to the agent.
  • Capability inventory: Subprocess execution via curl and jq.
  • Sanitization: No response validation is performed.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands including curl, jq, and the zero diagnostic tool to interact with the API and verify the environment.
  • [DATA_EXFILTRATION]: The skill transmits API keys to Arga Labs endpoints for authentication, which involves communication with external domains outside the standard whitelist.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 07:13 AM
Security Audit — agent-trust-hub — arga-labs