data-visualization

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute standard, read-only shell commands such as cat, grep, rg, and ls. These commands are used solely to inspect project configuration files (e.g., package.json, tailwind.config.js) and directory structures to identify existing chart libraries and components. This ensures the agent adheres to the project's existing architectural patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill templates interpolate external data into UI components and accessibility tables (using sr-only classes). While this represents a theoretical injection surface if the data source is untrusted, the skill utilizes standard React JSX escaping and does not use the data in sensitive execution contexts, network requests, or file-writing operations.
  • [SAFE]: The code samples provided use well-established and trusted open-source libraries (Recharts, D3, Lucide). No obfuscation, persistence mechanisms, or credential harvesting patterns were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:41 PM
Security Audit — agent-trust-hub — data-visualization