infographics

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a research phase using Perplexity Sonar to gather facts from the web, which are then interpolated into generation and review prompts in scripts/generate_infographic_ai.py. This creates an attack surface for indirect prompt injection.
  • Ingestion points: External data from perplexity/sonar-pro search results is stored in research_data['content'] and included in the prompt for the image generation model.
  • Boundary markers: The skill uses basic headers like RESEARCHED DATA AND FACTS (use these in the infographic): to separate research data from instructions, but lacks explicit directives for the model to ignore embedded malicious instructions within that data.
  • Capability inventory: The skill has capabilities to write files (images and JSON logs) to the local filesystem and perform network operations to OpenRouter APIs.
  • Sanitization: No sanitization or filtering is performed on the content retrieved from web searches before it is included in the prompt.
  • [COMMAND_EXECUTION]: The orchestration script scripts/generate_infographic.py uses subprocess.run to execute the local AI generation script generate_infographic_ai.py. This is implemented using secure practices (list-based arguments and a restricted environment), but it represents a dependency on local script execution.
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests to openrouter.ai to access Gemini and Perplexity models for research, image generation, and quality review. This is required for its primary functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — infographics