arga-labs
Pass
Audited by Gen Agent Trust Hub on Jun 30, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests data from external Arga Labs API endpoints, which creates an indirect prompt injection surface.
- Ingestion points: API response data fetched from URLs defined in documentation.
- Boundary markers: No delimiting instructions are provided to the agent.
- Capability inventory: Subprocess execution via curl and jq.
- Sanitization: No response validation is performed.
- [COMMAND_EXECUTION]: The skill utilizes shell commands including curl, jq, and the zero diagnostic tool to interact with the API and verify the environment.
- [DATA_EXFILTRATION]: The skill transmits API keys to Arga Labs endpoints for authentication, which involves communication with external domains outside the standard whitelist.
Audit Metadata