d3-viz
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: References the official D3.js library via the d3js.org CDN, which is a well-known service for this library.
- [PROMPT_INJECTION]: Demonstrates a surface for indirect prompt injection by processing external data to render visualisations. 1. Ingestion points: Untrusted data is ingested through various drawing functions in SKILL.md. 2. Boundary markers: The skill does not implement delimiters or ignore-instruction warnings for data inputs. 3. Capability inventory: The skill allows DOM manipulation, event listener registration, and custom event dispatching. 4. Sanitization: Code examples for tooltips and attribute updates do not include sanitization of data before rendering.
- [SAFE]: No malicious code, persistence mechanisms, or unauthorized data access patterns were identified in the skill content.
Audit Metadata