lov-mobile-infographic
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The function
logo_data_urlinscripts/infographic_cli.pyreads local files based on paths provided in the brand profile. It usesexpanduser()andis_absolute()to resolve the path, allowing access to any file the system user can read. The content is then base64-encoded and embedded in the generated HTML. While intended for logo images, this mechanism could be abused to access sensitive local data if an attacker can control the brand profile configuration.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided text for infographic generation and interpolates it into HTML templates. These templates are then rendered into PNG images using the Playwright browser automation library.\n - Ingestion points: User-provided text strings are passed via CLI arguments to
scripts/infographic_cli.py(scaffold command).\n - Boundary markers: Content is placed within HTML elements using simple string replacement markers like
{{TITLE}}and{{CLAIM}}in the templates located inassets/templates/.\n - Capability inventory: The skill uses Playwright to render HTML in
scripts/infographic_cli.py, performs local file reads, and writes HTML, PNG, and JSON files to the disk.\n - Sanitization: The skill performs minimal sanitization of the input text before embedding it into the HTML, relying on the calling agent or user to provide safe content.
Audit Metadata