tufte-data-visualization
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill provides instructions for the user to download and install its configuration files from a repository on GitHub (
https://github.com/aref-vc/tufte-claude-skill.git). This is the intended installation workflow for the skill. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided data to generate executable or renderable visualization code (HTML, SVG, and React/Recharts), creating a surface for potential injection.
- Ingestion points: User data supplied for visualization tasks (e.g., "make a chart") as described in SKILL.md.
- Boundary markers: No specific boundary markers or delimiters for user-supplied data are defined in the instructions.
- Capability inventory: The skill generates HTML, SVG, and React components based on user data (SKILL.md).
- Sanitization: There are no explicit instructions for validating or sanitizing user-provided data before it is interpolated into code templates.
Audit Metadata