d3-viz

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates patterns for displaying data in tooltips using the D3 .html() method, creating an attack surface for Cross-Site Scripting (XSS).
  • Ingestion points: The data parameter used across visualization functions in SKILL.md, assets/chart-template.jsx, and assets/interactive-template.jsx.
  • Boundary markers: None present to delimit or warn about untrusted content in the visualization templates.
  • Capability inventory: The skill utilizes D3.js for SVG rendering and direct DOM manipulation, specifically injecting raw HTML strings into the document for tooltips.
  • Sanitization: Absent; the code examples interpolate data values directly into HTML template literals without escaping or filtering.
  • [EXTERNAL_DOWNLOADS]: Fetches the D3.js library from the official d3js.org CDN in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — d3-viz