data-visualization

Warn

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the belt CLI for tasks such as authentication and running applications.
  • [REMOTE_CODE_EXECUTION]: It provides templates for executing arbitrary Python code (using matplotlib and numpy) and HTML content within remote execution environments like infsh/python-executor and infsh/html-to-image via the belt app run command.
  • [EXTERNAL_DOWNLOADS]: The skill references installation instructions and additional skill packages hosted on github.com/inference-sh.
  • [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection by encouraging the interpolation of data into executable code templates without providing sanitization or boundary markers.
  • Ingestion points: Chart data, titles, and annotations likely sourced from user input.
  • Boundary markers: Absent in the provided code templates.
  • Capability inventory: Execution of shell commands and remote code via the belt CLI.
  • Sanitization: None provided in the instructions or code examples.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 19, 2026, 02:15 AM
Security Audit — agent-trust-hub — data-visualization