data-visualization

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches installation metadata and additional skills from platforms and repositories associated with the service (e.g., inference.sh and GitHub repositories like belt-sh/cli).\n- [COMMAND_EXECUTION]: Uses the belt CLI tool to perform authentication and execute remote visualization tasks.\n- [DYNAMIC_EXECUTION]: Generates Python scripts and HTML snippets from local templates to be rendered into images by remote service applications.\n- [INDIRECT_PROMPT_INJECTION]:\n
  • Ingestion points: External data is processed via the --input field of the bash visualization commands, where it is interpolated into executable code strings.\n
  • Boundary markers: The provided templates do not utilize delimiters to separate data from instructions.\n
  • Capability inventory: The skill utilizes remote execution of Python and HTML rendering capabilities.\n
  • Sanitization: The instruction set does not include mechanisms for sanitizing or validating user-provided data before it is executed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:14 PM
Security Audit — agent-trust-hub — data-visualization