html-data-explorer
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill allows for the use of well-known external libraries such as Chart.js, D3, and Google Fonts via official CDN links for charting and typography.
- [DYNAMIC_EXECUTION]: The skill generates self-contained HTML files containing JavaScript to enable interactive filtering and data visualization. The instructions include specific mitigations against XSS, such as requiring the use of
textContentandcreateElementinstead ofinnerHTMLfor user-supplied data. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external datasets (CSVs, JSON, logs). While this presents a surface for potential injection, the instructions emphasize safe DOM manipulation and data inlining as JavaScript objects, which provides boundary markers against executing content embedded within the data.
Audit Metadata