science-scrollytelling

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes user-provided scientific papers, datasets, or text documents to generate functional web application code. \n
  • Ingestion points: User-provided research papers, datasets, and text documents. \n
  • Boundary markers: The skill lacks explicit delimiters or instructions to the agent to ignore potentially malicious commands embedded within the scientific source material. \n
  • Capability inventory: The agent has the capability to generate executable React, Tailwind CSS, and JavaScript code (using libraries like D3 or Recharts) based on the ingested content. \n
  • Sanitization: No sanitization or validation steps are prescribed for the content extracted from external documents before it is used to generate the application structure and logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 06:41 PM
Security Audit — agent-trust-hub — science-scrollytelling