figure-legend-writer
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified. The skill's behavior is consistent with its stated purpose of assisting in scientific writing.
- [PROMPT_INJECTION]: The instructions are focused on task-specific logic and do not contain attempts to bypass safety filters or override agent behavior.
- [DATA_EXFILTRATION]: No network access tools (e.g., curl, wget) or attempts to access sensitive system files (e.g., credentials, ssh keys) were detected. The Python script operates entirely on local data.
- [REMOTE_CODE_EXECUTION]: The provided Python script uses standard library modules (argparse, pathlib, typing, dataclasses, enum) and does not dynamically download or execute remote code.
- [SAFE]: While the skill ingests untrusted user input (figure descriptions), it lacks high-risk capabilities like network access or arbitrary command execution, effectively mitigating the risk of indirect injection attacks.
- [SAFE]: The skill includes an evaluation report (eval_report_figure-legend-writer_result.json) that claims various security passes; this was treated as non-authoritative data and found to be benign.
Audit Metadata