figure-legend-writer

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified. The skill's behavior is consistent with its stated purpose of assisting in scientific writing.
  • [PROMPT_INJECTION]: The instructions are focused on task-specific logic and do not contain attempts to bypass safety filters or override agent behavior.
  • [DATA_EXFILTRATION]: No network access tools (e.g., curl, wget) or attempts to access sensitive system files (e.g., credentials, ssh keys) were detected. The Python script operates entirely on local data.
  • [REMOTE_CODE_EXECUTION]: The provided Python script uses standard library modules (argparse, pathlib, typing, dataclasses, enum) and does not dynamically download or execute remote code.
  • [SAFE]: While the skill ingests untrusted user input (figure descriptions), it lacks high-risk capabilities like network access or arbitrary command execution, effectively mitigating the risk of indirect injection attacks.
  • [SAFE]: The skill includes an evaluation report (eval_report_figure-legend-writer_result.json) that claims various security passes; this was treated as non-authoritative data and found to be benign.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 01:51 AM
Security Audit — agent-trust-hub — figure-legend-writer