infographic-creator

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch the AntV Infographic library from unpkg.com, a well-known CDN for public software packages. The library itself is a recognized tool from a well-known organization.
  • [REMOTE_CODE_EXECUTION]: The generated HTML output executes code from a remote source at runtime to render the visualization. This is a standard and intended function for this visualization tool.
  • [PROMPT_INJECTION]: The skill processes user-supplied text to generate visualizations. While there is a potential for indirect prompt injection (e.g., if user text contains backticks that break the JavaScript string literal in the generated HTML), this is a common attack surface for data-to-HTML tools and is handled as a minor risk given the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 03:02 PM
Security Audit — agent-trust-hub — infographic-creator