Who Tests the Testers? Systematic Enumeration and Coverage Audit of LLM Agent Tool Call Safety
Xuan Chen, Lu Yan, Ruqi Zhang, Xiangyu Zhang
cs.SE, cs.CR
Submitted: 2026-08-15
Updated: 2026-08-18
License: http://creativecommons.org/licenses/by/4.0/
The gist: Large Language Model (LLM) agents increasingly act through external tools, making their safety contingent on tool-call workflows rather than text generation alone.
Terminology
Abstract
Large Language Model (LLM) agents increasingly act through external tools, making their safety contingent on tool-call workflows rather than text generation alone. While recent benchmarks evaluate agents across diverse environments and risk categories, a fundamental question remains unanswered: how complete are existing test suites, and what unsafe interaction patterns persist even after an agent passes the benchmark? We propose SafeAudit, a meta-audit framework that addresses this gap through two contributions. First, an LLM-based enumerator that systematically generates test cases by enumerating valid tool-call workflows and diverse user scenarios. Second, we introduce rule-resistance, a non-semantic, quantitative metric that distills compact safety rules from existing benchmarks and identifies unsafe interaction patterns that remain uncovered under those rules. Across 3 benchmarks and 12 environments, SafeAudit uncovers more than 20% residual unsafe behaviors that existing benchmarks fail to expose, with coverage growing monotonically as the testing budget increases. Our results highlight significant completeness gaps in current safety evaluation and motivate meta-auditing as a necessary complement to benchmark-based agent safety testing.
Sources
- Why Do Multi-Agent LLM Systems Fail?
- Mapping the Design Space of User Experience for Computer Use Agents
- LLM Agents for Education: Advances and Applications
- TAI3: Testing Agent Integrity in Interpreting User Intent
- The Llama 3 Herd of Models
- AgentLAB: Benchmarking LLM Agents against Long-Horizon Attacks
- Quantifying Language Models' Sensitivity to Spurious Features in Prompt Design or: How I learned to start worrying about prompt formatting
- OS-Harm: A Benchmark for Measuring Safety of Computer Use Agents
- IS-Bench: Evaluating Interactive Safety of VLM-Driven Embodied Agents in Daily Household Tasks
- AgentAuditor: Human-Level Safety and Security Evaluation for LLM Agents
- PromptArmor: Simple yet Effective Prompt Injection Defenses
- Helpful to a Fault: Measuring Illicit Assistance in Multi-Turn, Multilingual LLM Agents
- ToolSafe: Enhancing Tool Invocation Safety of LLM-based agents via Proactive Step-level Guardrail and Feedback
- SafeArena: Evaluating the Safety of Autonomous Web Agents
- Qwen2.5 Technical Report
- The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions
- $\tau$-bench: A Benchmark for Tool-Agent-User Interaction in Real-World Domains
- Self-Consistency Improves Chain of Thought Reasoning in Language Models
- Agent-SafetyBench: Evaluating the Safety of LLM Agents
Related papers
- Falsification-Based Verification of LLM-Generated Optimization Models: Sound Test Batteries and Their Detection Limits
- GitSkills: A Dataset of Agent Skills on GitHub
- SABER: Benchmarking Operational Safety of LLM Coding Agents in Stateful Project Workspaces
- PackMonitor: Enabling Zero Package Hallucinations Through Decoding-Time Monitoring
- IntentCoding: Amplifying User Intent in Code Generation
- Incentives and Outcomes in Bug Bounties