light-figure-drawing

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The script examples/example_framework_render.py utilizes subprocess.run to call the Graphviz dot utility for rendering diagrams. The implementation follows security best practices by passing arguments as a list and avoiding shell execution, with source file paths hardcoded to internal examples.\n- [SAFE]: The utility scripts scripts/figure_export.py and scripts/figure_integrity_lint.py perform local file read operations to analyze plot code and measure dimensions. These operations use standard parsing libraries and are restricted to the local environment, consistent with the skill's purpose of preparing academic figures.\n- [SAFE]: The skill incorporates extensive documentation on ethical research practices, including publisher-specific guidelines for figure integrity and AI-generated content policies. It references well-known academic institutions and publishers for compliance data without performing unsafe remote operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 05:05 AM
Security Audit — agent-trust-hub — light-figure-drawing