infographics
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a research phase using Perplexity Sonar to gather facts from the web, which are then interpolated into generation and review prompts in
scripts/generate_infographic_ai.py. This creates an attack surface for indirect prompt injection. - Ingestion points: External data from
perplexity/sonar-prosearch results is stored inresearch_data['content']and included in the prompt for the image generation model. - Boundary markers: The skill uses basic headers like
RESEARCHED DATA AND FACTS (use these in the infographic):to separate research data from instructions, but lacks explicit directives for the model to ignore embedded malicious instructions within that data. - Capability inventory: The skill has capabilities to write files (images and JSON logs) to the local filesystem and perform network operations to OpenRouter APIs.
- Sanitization: No sanitization or filtering is performed on the content retrieved from web searches before it is included in the prompt.
- [COMMAND_EXECUTION]: The orchestration script
scripts/generate_infographic.pyusessubprocess.runto execute the local AI generation scriptgenerate_infographic_ai.py. This is implemented using secure practices (list-based arguments and a restricted environment), but it represents a dependency on local script execution. - [EXTERNAL_DOWNLOADS]: The skill performs network requests to
openrouter.aito access Gemini and Perplexity models for research, image generation, and quality review. This is required for its primary functionality.
Audit Metadata