displaying-timelines

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and display of data from external, untrusted sources such as social activity feeds, notifications, and system audit logs.\n
  • Ingestion points: Untrusted data enters the agent context through the activity feed and audit log components described in SKILL.md and references/audit-logs.md.\n
  • Boundary markers: The provided documentation and placeholder examples do not currently implement explicit delimiters or instructions to ignore commands embedded within the external data strings.\n
  • Capability inventory: The skill utilizes local utility scripts for data generation and benchmarking, and it supports real-time data flow via WebSockets.\n
  • Sanitization: There is no explicit mention of sanitization or escaping logic for external content in the provided implementation guides.\n- [EXTERNAL_DOWNLOADS]: The skill suggests the use of well-known and widely adopted third-party libraries for UI implementation, including react-chrono, react-vertical-timeline-component, @svar/gantt, react-big-calendar, and FullCalendar.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:34 AM
Security Audit — agent-trust-hub — displaying-timelines