d3-viz
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines visualization components that ingest and render untrusted external data. Code examples in SKILL.md and assets/interactive-template.jsx use the D3 .html() method to display data properties like label and category in tooltips. This pattern represents a surface for Cross-Site Scripting (XSS) if the input data contains malicious scripts. \n
- Ingestion points: data prop in BasicChart, InteractiveChart, and arguments to functions like drawVisualization. \n
- Boundary markers: None. \n
- Capability inventory: SVG rendering and DOM manipulation. \n
- Sanitization: Missing; data is directly interpolated into HTML tooltips. \n- [EXTERNAL_DOWNLOADS]: Fetches the D3.js library from the official d3js.org domain.
Audit Metadata