d3js-visualization
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documentation includes code snippets for interactive tooltips that use the
.html()method to render data-driven content (e.g.,d.name). This creates a vulnerability surface where malicious instructions or scripts embedded in external data could be executed in the user's browser context if the data is not sanitized. - Ingestion points: The
dataparameter in chart creation functions (createBarChart,createLineChart,createPieChart) and mouse event handlers inSKILL.md. - Boundary markers: None provided to distinguish between data and instructions.
- Capability inventory: The code utilizes
d3.select(...).html(...)which interprets strings as HTML/JavaScript. - Sanitization: No sanitization or escaping logic is included in the provided templates.
Audit Metadata