matplotlib

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of prompt injection or instruction override patterns detected. The skill contains a standard 'Agent operating procedure' and 'Integrity rules' that reinforce safety, truthfulness, and user confirmation for sensitive actions.
  • [DATA_EXFILTRATION]: No sensitive file paths, credential harvesting, or unauthorized network operations were identified. The skill correctly references official documentation at matplotlib.org and GitHub, both of which are trusted sources.
  • [OBFUSCATION]: No hidden content, encoded strings, homoglyphs, or zero-width characters were found across any of the analyzed files.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform remote script execution or download code from untrusted sources. It uses the standard 'uv' package manager to install the well-known 'matplotlib' and 'ipympl' libraries.
  • [COMMAND_EXECUTION]: Shell commands are restricted to package management ('uv add') and running local template scripts, which is expected behavior for a developer-oriented skill.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes data to generate visualizations, it includes explicit instructions for the agent to validate results, avoid fabrication, and maintain data integrity, effectively mitigating injection risks.
  • [PRIVILEGE_ESCALATION]: No attempts to acquire elevated permissions or modify system configurations were detected.
  • [DYNAMIC_EXECUTION]: The provided Python scripts use standard plotting APIs and do not utilize unsafe dynamic execution functions like 'eval()' or 'exec()' on external data.
  • [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or private secrets were found. The skill does not instruct the agent to handle or store credentials unsafely.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — matplotlib