gemini-d3js-skill
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection.
- Ingestion points: The
dataproperty in theInteractiveChartcomponent (assets/interactive-template.jsx) and data variables described in SKILL.md. - Boundary markers: No delimiters or safety instructions are used to separate untrusted data from the rendering logic.
- Capability inventory: The skill leverages D3.js for DOM manipulation, specifically using the
.html()method to render tooltips. - Sanitization: String fields from the input data (such as
labelandcategory) are interpolated directly into HTML strings for tooltips without escaping or validation. - [COMMAND_EXECUTION]: The file
scripts/evaluate.pyis an executable script. While its current functionality is limited to a benign status message, it establishes a mechanism for local code execution within the skill's environment.
Audit Metadata