scientific-visualization

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a comprehensive environment for scientific figure design, emphasizing data honesty and redundant encoding for accessibility. All operations are designed to be local and network-free.
  • [COMMAND_EXECUTION]: The bundled Python scripts (image_metadata.py, palette_audit.py, figure_export.py, etc.) are intended for local execution via the uv tool. They include advanced safety features, such as rejecting symlinks for inputs and outputs, enforcing a 200MB input file size limit, and utilizing atomic writes with restricted permissions (0o600) to protect output data.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes external figure files, which constitutes a potential injection surface. This is mitigated by strict validation: SVG parsing includes explicit checks to forbid internal DTD and entity declarations (preventing XXE attacks), and raster image processing uses Pillow's decompression bomb protection to prevent denial-of-service via massive pixel dimensions.
  • [EXTERNAL_DOWNLOADS]: The documentation provides example commands that use pinned versions of reputable scientific libraries (matplotlib, seaborn, plotly, pillow, pypdf). These dependencies are sourced from the standard PyPI registry and are widely trusted in the scientific computing community.
  • [DYNAMIC_EXECUTION]: The scripts load bundled local assets (like color_palettes.py) using standard Python import utilities. There is no evidence of dynamic code generation or execution from untrusted or remote sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — scientific-visualization