datell-visual-report-preview
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill generates HTML reports that include references to popular visualization libraries (ECharts and ApexCharts) hosted on the well-known
cdn.jsdelivr.netservice. - [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing user-provided metrics to generate HTML reports.
- Ingestion points: User-provided metrics are normalized into a report schema within the
SKILL.mdworkflow. - Boundary markers: No explicit instructions are provided for the agent to use boundary markers or delimiters when interpolating user data into the HTML structure.
- Capability inventory: The skill can generate
.htmlartifacts and call thedatell_generate_chartMCP tool. - Sanitization: There are no instructions for sanitizing or escaping user-provided input before it is embedded in the final HTML document.
Audit Metadata