d3-visualization

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill documentation and resources are focused on teaching legitimate D3.js visualization techniques.
  • [EXTERNAL_DOWNLOADS]: The skill references the official D3.js library via well-known content delivery networks, specifically d3js.org and Skypack. These are standard industry sources for web development libraries.
  • [DATA_EXPOSURE]: The skill demonstrates how to load visualization data from local CSV and JSON files using standard D3 methods. There is no evidence of attempts to access sensitive system files or environment variables.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data which constitutes a potential injection surface. * Ingestion points: The skill utilizes d3.csv and d3.json to load external datasets in resources/getting-started.md and resources/workflows.md. * Boundary markers: No explicit delimiters or warnings to ignore instructions within the data are present in the code snippets. * Capability inventory: The skill performs DOM manipulation, SVG rendering, and event handling via D3.js. * Sanitization: Code examples, such as the tooltip implementation in resources/transitions-interactions.md, do not explicitly demonstrate sanitization of data attributes before rendering them as HTML.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 06:00 AM
Security Audit — agent-trust-hub — d3-visualization