alterlab-figure-qa

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted data (source data files and rendered figures) which represents an indirect prompt injection surface. This is considered safe as the logic is limited to local diagnostic assertions. Evidence: \n
  • Ingestion points: User-provided source data and rendered figure files mentioned in SKILL.md and evals.json. \n
  • Boundary markers: Absent in prompt interpolation logic. \n
  • Capability inventory: Shell command execution via Bash(python:) and Bash(uv:) specified in SKILL.md. \n
  • Sanitization: No explicit sanitization or validation of data content described in the code recipes. \n- [COMMAND_EXECUTION]: The skill uses Python and uv tools to execute analysis scripts using recipes from references/figure_qa_checklist.md. These operations are restricted to Matplotlib and Pillow API calls for figure inspection and do not involve network access or sensitive file access.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 11:26 PM
Security Audit — agent-trust-hub — alterlab-figure-qa