paper-figures
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill is designed to generate a Python script (
plot.py) based on user-provided data and natural-language descriptions, and then execute that script to produce a PNG figure. - Evidence:
SKILL.mdStep 6: "Write the script and run it" and "Execute it withpython plot.py". This involves the agent creating executable code and running it in the local environment. - [INDIRECT_PROMPT_INJECTION]: The skill accepts external data sources as input, which are used to determine the content and structure of generated scripts. This represents a vulnerability surface where malicious data could attempt to influence the agent's code generation.
- Ingestion points:
SKILL.mdidentifies "CSV file path, JSON, or inline table" as primary data inputs. - Boundary markers: There are no explicit instructions for the agent to use delimiters or ignore instructions embedded within the data content.
- Capability inventory: The skill utilizes the
executetool to run generated Python scripts and a validation script, alongsidewrite_fileandread_filetools. - Sanitization: The instructions lack specific requirements for sanitizing or validating the contents of the ingested data before processing it for code generation.
- [COMMAND_EXECUTION]: The skill performs shell commands to install dependencies and run an internal validation tool.
- Evidence:
SKILL.mdinstructs the agent to runpip install matplotlib pandas numpy scipyandpython scripts/validate_figure.pyas part of the setup and core workflow.
Audit Metadata