chart-visualization

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes a local Node.js script (scripts/generate.js) to handle the logic for chart generation and remote API communication.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: User data is sent to antv-studio.alipay.com for chart rendering. This operation is the primary functional purpose of the skill and targets a well-known service provider domain.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user data and incorporates it into JSON payloads for the visualization service, creating an attack surface for indirect prompt injection.
  • Ingestion points: Data provided by the user is mapped to the args field and passed to the script via command-line arguments in SKILL.md.
  • Boundary markers: The skill lacks explicit delimiters or instructions to the model to ignore or escape embedded instructions within the user data.
  • Capability inventory: The visualization script possesses network capabilities (fetch) to a specific remote domain and file system access for reading configuration or local data.
  • Sanitization: There is no evidence of sanitization or escaping of user-provided strings before they are transmitted to the external API or processed by the script.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — chart-visualization