d3-viz

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: References the official D3.js library via the d3js.org CDN, which is a well-known service for this library.
  • [PROMPT_INJECTION]: Demonstrates a surface for indirect prompt injection by processing external data to render visualisations. 1. Ingestion points: Untrusted data is ingested through various drawing functions in SKILL.md. 2. Boundary markers: The skill does not implement delimiters or ignore-instruction warnings for data inputs. 3. Capability inventory: The skill allows DOM manipulation, event listener registration, and custom event dispatching. 4. Sanitization: Code examples for tooltips and attribute updates do not include sanitization of data before rendering.
  • [SAFE]: No malicious code, persistence mechanisms, or unauthorized data access patterns were identified in the skill content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 11:56 PM
Security Audit — agent-trust-hub — d3-viz