paper-figures

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill is designed to generate a Python script (plot.py) based on user-provided data and natural-language descriptions, and then execute that script to produce a PNG figure.
  • Evidence: SKILL.md Step 6: "Write the script and run it" and "Execute it with python plot.py". This involves the agent creating executable code and running it in the local environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts external data sources as input, which are used to determine the content and structure of generated scripts. This represents a vulnerability surface where malicious data could attempt to influence the agent's code generation.
  • Ingestion points: SKILL.md identifies "CSV file path, JSON, or inline table" as primary data inputs.
  • Boundary markers: There are no explicit instructions for the agent to use delimiters or ignore instructions embedded within the data content.
  • Capability inventory: The skill utilizes the execute tool to run generated Python scripts and a validation script, alongside write_file and read_file tools.
  • Sanitization: The instructions lack specific requirements for sanitizing or validating the contents of the ingested data before processing it for code generation.
  • [COMMAND_EXECUTION]: The skill performs shell commands to install dependencies and run an internal validation tool.
  • Evidence: SKILL.md instructs the agent to run pip install matplotlib pandas numpy scipy and python scripts/validate_figure.py as part of the setup and core workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 08:21 AM