scientific-visualization
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a comprehensive environment for scientific figure design, emphasizing data honesty and redundant encoding for accessibility. All operations are designed to be local and network-free.
- [COMMAND_EXECUTION]: The bundled Python scripts (
image_metadata.py,palette_audit.py,figure_export.py, etc.) are intended for local execution via theuvtool. They include advanced safety features, such as rejecting symlinks for inputs and outputs, enforcing a 200MB input file size limit, and utilizing atomic writes with restricted permissions (0o600) to protect output data. - [INDIRECT_PROMPT_INJECTION]: The skill analyzes external figure files, which constitutes a potential injection surface. This is mitigated by strict validation: SVG parsing includes explicit checks to forbid internal DTD and entity declarations (preventing XXE attacks), and raster image processing uses Pillow's decompression bomb protection to prevent denial-of-service via massive pixel dimensions.
- [EXTERNAL_DOWNLOADS]: The documentation provides example commands that use pinned versions of reputable scientific libraries (
matplotlib,seaborn,plotly,pillow,pypdf). These dependencies are sourced from the standard PyPI registry and are widely trusted in the scientific computing community. - [DYNAMIC_EXECUTION]: The scripts load bundled local assets (like
color_palettes.py) using standard Python import utilities. There is no evidence of dynamic code generation or execution from untrusted or remote sources.
Audit Metadata