Write the Giskard scan description carefully, since every test case derives from it. Use vulnerability_scan for exploration and generate_suite when you want to review or version the scenarios before running. Remember the judge is an LLM, so verdicts are judgments, not exact matches.

Context: Official Giskard docs (how the scan works): documents the scan pipeline agents misunderstand. Everything derives from the description you pass: say who the agent serves, what it may do, and what it must refuse. Generators turn that into scenarios; the suite is the collection of scenarios; an LLM judge reads each finished conversation and decides pass or fail, with no string matching and no ground-truth answers. Two modes: vulnerability_scan or quality_scan generates and runs in one call, while generate_suite stops after generation so you can inspect, edit, save, and run later.