create-figure

Fail

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The module matplotlib_backend.py utilizes the Python eval() function within generate_phase_portrait, generate_3d_surface, and generate_3d_contour to evaluate mathematical functions passed as strings from the agent or user. Although the skill attempts to sandbox this by clearing __builtins__, this pattern remains susceptible to sophisticated Python sandbox escape techniques.
  • [DATA_EXFILTRATION]: Visualization commands in fixture_graph.py and d3_commands.py do not perform sanitization on the --output file path. This lack of validation allows for potential Path Traversal attacks, where an agent could be instructed to write or overwrite sensitive files (e.g., ~/.ssh/authorized_keys) by providing absolute paths or directory traversal sequences (../).
  • [COMMAND_EXECUTION]: Several modules, including graphviz_backend.py, mermaid_backend.py, analysis.py, and d3_backend.py, execute external system binaries and scripts using subprocess.run. Tools called include dot (Graphviz), mmdc (Mermaid CLI), pyreverse, and playwright. While these are used for the skill's primary purpose of figure generation, they represent a significant attack surface if inputs are not strictly controlled.
  • [EXTERNAL_DOWNLOADS]: Interactive D3.js visualization templates in the d3/gallery/ directory dynamically load libraries and assets from cdn.jsdelivr.net at runtime. While this is a well-known service, it introduces a dependency on external content during the rendering process.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — create-figure