plotting-agent
Warn
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/paperbanana_render.pyperforms dynamic loading of Python modules. It usessys.path.insert(0, str(pb_path))to add a directory path, obtained from thePAPERBANANA_PATHenvironment variable, to the Python search path. It then proceeds to import multiple agents and utilities (e.g.,agents.planner_agent,utils.paperviz_processor) from that location. This allows for the execution of arbitrary code from a path that is not part of the skill's distributed files. - [EXTERNAL_DOWNLOADS]: The documentation in
references/paperbanana-cookbook.mdinstructs users to download external code by cloning a third-party repository (https://github.com/dwzhu-pku/PaperBanana) and installing dependencies from an unversionedrequirements.txt. While the download is not performed automatically by the skill, the skill is designed to integrate and execute this external code. - [REMOTE_CODE_EXECUTION]: By combining the instructions to clone an external repository with the dynamic loading mechanism in
scripts/paperbanana_render.py, the skill facilitates the execution of code retrieved from a remote, third-party source. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from
workspace/inputs/idea.mdandworkspace/inputs/experimental_log.mdto generate figure captions and plotting specifications. If these files contain malicious instructions, the agent might inadvertently follow them during the captioning or critique phases. - Ingestion points:
workspace/inputs/idea.mdandworkspace/inputs/experimental_log.mdare read inSKILL.mdand passed to rendering scripts. - Boundary markers: None identified in the caption prompt provided in
references/caption-prompt.md. - Capability inventory: The skill has access to file writing (
workspace/figures/), shell execution (rendering matplotlib), and dynamic code loading. - Sanitization: The skill does not appear to sanitize the extracted data before interpolating it into prompts or scripts.
Audit Metadata