plotting-agent

Warn

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/paperbanana_render.py performs dynamic loading of Python modules. It uses sys.path.insert(0, str(pb_path)) to add a directory path, obtained from the PAPERBANANA_PATH environment variable, to the Python search path. It then proceeds to import multiple agents and utilities (e.g., agents.planner_agent, utils.paperviz_processor) from that location. This allows for the execution of arbitrary code from a path that is not part of the skill's distributed files.
  • [EXTERNAL_DOWNLOADS]: The documentation in references/paperbanana-cookbook.md instructs users to download external code by cloning a third-party repository (https://github.com/dwzhu-pku/PaperBanana) and installing dependencies from an unversioned requirements.txt. While the download is not performed automatically by the skill, the skill is designed to integrate and execute this external code.
  • [REMOTE_CODE_EXECUTION]: By combining the instructions to clone an external repository with the dynamic loading mechanism in scripts/paperbanana_render.py, the skill facilitates the execution of code retrieved from a remote, third-party source.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from workspace/inputs/idea.md and workspace/inputs/experimental_log.md to generate figure captions and plotting specifications. If these files contain malicious instructions, the agent might inadvertently follow them during the captioning or critique phases.
  • Ingestion points: workspace/inputs/idea.md and workspace/inputs/experimental_log.md are read in SKILL.md and passed to rendering scripts.
  • Boundary markers: None identified in the caption prompt provided in references/caption-prompt.md.
  • Capability inventory: The skill has access to file writing (workspace/figures/), shell execution (rendering matplotlib), and dynamic code loading.
  • Sanitization: The skill does not appear to sanitize the extracted data before interpolating it into prompts or scripts.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 28, 2026, 01:43 AM
Security Audit — agent-trust-hub — plotting-agent