d3-viz

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via untrusted data processing. It provides templates that use the D3 .html() method to render tooltips based on input data, which could execute malicious scripts or render deceptive content if the data labels or values are attacker-controlled.
  • Ingestion points: The data object passed to visualization functions in SKILL.md, assets/chart-template.jsx, and assets/interactive-template.jsx.
  • Boundary markers: Absent; there are no delimiters or instructions provided to the agent or the rendering logic to ignore embedded HTML/scripts in the data fields.
  • Capability inventory: The skill focus is on DOM manipulation within a browser context; it does not request or use capabilities for subprocess execution, file system writes, or unauthorized network operations.
  • Sanitization: Absent; the code examples in SKILL.md and assets/interactive-template.jsx interpolate data properties (like d.label) directly into HTML strings for tooltip display without escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:18 PM
Security Audit — agent-trust-hub — d3-viz