chart-visualization
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes a local Node.js script (
scripts/generate.js) to handle the logic for chart generation and remote API communication. - [DATA_EXPOSURE_AND_EXFILTRATION]: User data is sent to
antv-studio.alipay.comfor chart rendering. This operation is the primary functional purpose of the skill and targets a well-known service provider domain. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user data and incorporates it into JSON payloads for the visualization service, creating an attack surface for indirect prompt injection.
- Ingestion points: Data provided by the user is mapped to the
argsfield and passed to the script via command-line arguments inSKILL.md. - Boundary markers: The skill lacks explicit delimiters or instructions to the model to ignore or escape embedded instructions within the user data.
- Capability inventory: The visualization script possesses network capabilities (
fetch) to a specific remote domain and file system access for reading configuration or local data. - Sanitization: There is no evidence of sanitization or escaping of user-provided strings before they are transmitted to the external API or processed by the script.
Audit Metadata