data-visualization

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and downloads documentation from https://raw.githubusercontent.com/inference-sh/skills/refs/heads/main/cli-install.md.
  • [REMOTE_CODE_EXECUTION]: Instructions include the installation of the belt-sh/cli package using npx, which executes remote code during setup.
  • [COMMAND_EXECUTION]: The skill executes shell commands via the belt tool to run Python scripts and render HTML content.
  • [PROMPT_INJECTION]: The skill contains an indirect prompt injection vulnerability. Ingestion points: Data is passed to the input parameter of belt app run. Boundary markers: There are no delimiters to separate data from instructions. Capability inventory: Access to infsh/python-executor and infsh/html-to-image for code and script execution. Sanitization: Data is interpolated directly into code strings without escaping or validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 10:40 PM
Security Audit — agent-trust-hub — data-visualization