figure-lab

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the uv tool to manage its Python environment and execute CLI tasks. It also implements a 'promote' feature that updates catalog files in a sibling skill to register new visualization types, which is consistent with its intended purpose.
  • [EXTERNAL_DOWNLOADS]: Fetches the D3.js visualization library from the trusted jsDelivr CDN (cdn.jsdelivr.net).
  • [SAFE]: Implements robust sanitization of user-provided data and descriptions using JSON serialization and HTML escaping, effectively preventing code injection within the generated visualizations.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — figure-lab