matplotlib
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No evidence of prompt injection or instruction override patterns detected. The skill contains a standard 'Agent operating procedure' and 'Integrity rules' that reinforce safety, truthfulness, and user confirmation for sensitive actions.
- [DATA_EXFILTRATION]: No sensitive file paths, credential harvesting, or unauthorized network operations were identified. The skill correctly references official documentation at matplotlib.org and GitHub, both of which are trusted sources.
- [OBFUSCATION]: No hidden content, encoded strings, homoglyphs, or zero-width characters were found across any of the analyzed files.
- [REMOTE_CODE_EXECUTION]: The skill does not perform remote script execution or download code from untrusted sources. It uses the standard 'uv' package manager to install the well-known 'matplotlib' and 'ipympl' libraries.
- [COMMAND_EXECUTION]: Shell commands are restricted to package management ('uv add') and running local template scripts, which is expected behavior for a developer-oriented skill.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes data to generate visualizations, it includes explicit instructions for the agent to validate results, avoid fabrication, and maintain data integrity, effectively mitigating injection risks.
- [PRIVILEGE_ESCALATION]: No attempts to acquire elevated permissions or modify system configurations were detected.
- [DYNAMIC_EXECUTION]: The provided Python scripts use standard plotting APIs and do not utilize unsafe dynamic execution functions like 'eval()' or 'exec()' on external data.
- [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or private secrets were found. The skill does not instruct the agent to handle or store credentials unsafely.
Audit Metadata