visualize
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted documentation and markdown files from the repository to extract facts for visualizations. This content could contain instructions designed to manipulate the agent's behavior during the analysis phase.
- Ingestion points: Reads repository files including
SUMMARY.md,phase-XX-*.md,section-XX-*.md, and arbitrary user-provided markdown or document files. - Boundary markers: The instructions lack explicit boundary markers or instructions for the agent to treat source content as data rather than instructions, although output escaping is required.
- Capability inventory: The skill has capabilities to read files, write HTML files, and execute shell commands for timestamp generation.
- Sanitization: The workflow explicitly mandates escaping source-derived text before inserting it into HTML templates to prevent cross-site scripting (XSS).
- [EXTERNAL_DOWNLOADS]: The HTML templates generate visualizations that load the Mermaid diagramming library from a well-known public CDN.
- Evidence: The script tag in templates uses
https://cdn.jsdelivr.net/npm/mermaid@11/dist/mermaid.esm.min.mjs. - [COMMAND_EXECUTION]: The skill instructions direct the agent to use a shell command to generate unique timestamps for source-less visualization folders.
- Evidence:
SKILL.mdspecifies generating timestamps withdate +%y%m%d-%H%M.
Audit Metadata