viz
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill provides a Python script template in
references/mode-infographic.mdand directs the agent to populate it with external content and execute it. This is a high-risk pattern because the script interpolates untrusteddocument_textdirectly into a triple-quoted string. A malicious source could provide content containing triple-quotes to break out of the string context and execute arbitrary Python code on the host system. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from a variety of untrusted external sources, exposing it to indirect injection attacks.
- Ingestion points: The skill fetches content from arbitrary URLs via
web_fetchand reads files from/mnt/user-data/uploads/(PDF, DOCX, CSV) and/mnt/transcripts/. - Boundary markers: No delimiters or "ignore instructions" warnings are used when interpolating external content into the Gemini API prompt or the Python script template.
- Capability inventory: The skill possesses the ability to execute Python scripts (with network and disk access), perform web searches/fetches, and publish interactive apps to an external platform.
- Sanitization: There is no evidence of sanitization, filtering, or validation of the external data before it is processed or used in execution contexts.
- [COMMAND_EXECUTION]: The workflow requires the agent to execute code at runtime (via Python) to interact with the Gemini API and handle file outputs, providing a direct mechanism for code-based attacks if the generation logic is compromised.
- [EXTERNAL_DOWNLOADS]: The skill references external dependencies and services. It loads
Chart.jsfromcdnjs.cloudflare.cominreferences/mode-publish.mdandreferences/mode-visualize.md. It also performs network requests togenerativelanguage.googleapis.comto interact with Gemini. - [DATA_EXFILTRATION]: The skill is designed to transmit user content to external services, including Google's Gemini API and the HeyGenverse platform (
heygenverse.com). While these actions support the skill's features, they represent a data exfiltration surface for any sensitive information contained in the ingested documents or transcripts.
Recommendations
- AI detected serious security threats
Audit Metadata