gpt-vis

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the @antv/gpt-vis package and the unpkg.com CDN. These are standard resources for web visualization development and belong to established technology providers.
  • [DYNAMIC_EXECUTION]: The skill provides instructions for the agent to generate functional HTML and JavaScript code. This code generation is the primary intended purpose of the skill, allowing users to render charts directly.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided data to generate complex visualization summaries and configurations. This represents a standard data processing surface for LLM-based tools.
  • Ingestion points: User intent and data inputs described in the generation steps.
  • Boundary markers: None explicitly mentioned in the skill instructions.
  • Capability inventory: The skill generates code and configurations for external rendering; it does not directly invoke execution tools.
  • Sanitization: No specific sanitization or filtering logic is prescribed for the input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 07:53 AM
Security Audit — agent-trust-hub — gpt-vis