d3-viz
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill demonstrates patterns for displaying data in tooltips using the D3
.html()method, creating an attack surface for Cross-Site Scripting (XSS). - Ingestion points: The
dataparameter used across visualization functions inSKILL.md,assets/chart-template.jsx, andassets/interactive-template.jsx. - Boundary markers: None present to delimit or warn about untrusted content in the visualization templates.
- Capability inventory: The skill utilizes D3.js for SVG rendering and direct DOM manipulation, specifically injecting raw HTML strings into the document for tooltips.
- Sanitization: Absent; the code examples interpolate data values directly into HTML template literals without escaping or filtering.
- [EXTERNAL_DOWNLOADS]: Fetches the D3.js library from the official d3js.org CDN in
SKILL.md.
Audit Metadata