light-figure-drawing

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes the Graphviz dot binary via subprocess.run within examples/example_framework_render.py to render framework diagrams. Additionally, the documentation describes the use of established command-line tools such as inkscape, mermaid-cli, and drawio for specialized figure manipulation and export.
  • [EXTERNAL_DOWNLOADS]: The skill references several well-known scientific software packages and Python dependencies, including matplotlib, seaborn, plotly, altair, kaleido, vl-convert-python, colorspacious, pypdf, and Pillow. These are standard and trusted tools used throughout the research and data science communities.
  • [PROMPT_INJECTION]: A review of the instructional content and skill metadata revealed no evidence of prompt injection or attempts to override the AI agent's safety parameters.
  • [DATA_EXFILTRATION]: No unauthorized access to sensitive system files or unexpected network operations were detected. Mentions of curl in the documentation strictly refer to the verification of official publication standards from well-known scientific journals.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 08:01 AM
Security Audit — agent-trust-hub — light-figure-drawing