data-visualization
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute standard, read-only shell commands such as
cat,grep,rg, andls. These commands are used solely to inspect project configuration files (e.g.,package.json,tailwind.config.js) and directory structures to identify existing chart libraries and components. This ensures the agent adheres to the project's existing architectural patterns. - [INDIRECT_PROMPT_INJECTION]: The skill templates interpolate external data into UI components and accessibility tables (using
sr-onlyclasses). While this represents a theoretical injection surface if the data source is untrusted, the skill utilizes standard React JSX escaping and does not use the data in sensitive execution contexts, network requests, or file-writing operations. - [SAFE]: The code samples provided use well-established and trusted open-source libraries (Recharts, D3, Lucide). No obfuscation, persistence mechanisms, or credential harvesting patterns were detected.
Audit Metadata