create-figure
Fail
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The module
matplotlib_backend.pyutilizes the Pythoneval()function withingenerate_phase_portrait,generate_3d_surface, andgenerate_3d_contourto evaluate mathematical functions passed as strings from the agent or user. Although the skill attempts to sandbox this by clearing__builtins__, this pattern remains susceptible to sophisticated Python sandbox escape techniques. - [DATA_EXFILTRATION]: Visualization commands in
fixture_graph.pyandd3_commands.pydo not perform sanitization on the--outputfile path. This lack of validation allows for potential Path Traversal attacks, where an agent could be instructed to write or overwrite sensitive files (e.g.,~/.ssh/authorized_keys) by providing absolute paths or directory traversal sequences (../). - [COMMAND_EXECUTION]: Several modules, including
graphviz_backend.py,mermaid_backend.py,analysis.py, andd3_backend.py, execute external system binaries and scripts usingsubprocess.run. Tools called includedot(Graphviz),mmdc(Mermaid CLI),pyreverse, andplaywright. While these are used for the skill's primary purpose of figure generation, they represent a significant attack surface if inputs are not strictly controlled. - [EXTERNAL_DOWNLOADS]: Interactive D3.js visualization templates in the
d3/gallery/directory dynamically load libraries and assets fromcdn.jsdelivr.netat runtime. While this is a well-known service, it introduces a dependency on external content during the rendering process.
Recommendations
- AI detected serious security threats
Audit Metadata