chart-image
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The fulfillment examples provided in
CAPABILITY.mdfor thelineChart,barChart, andareaChartmethods interpolate user-provided parameters like${title}and${JSON.stringify(data)}directly into shell command strings. This practice is vulnerable to command injection if the agent does not properly escape or sanitize the input values before execution. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted data that could contain malicious instructions designed to influence the agent's behavior or manipulate the generated output.
- Ingestion points: Parameters such as
data,title, andoptionsin the capability definitions are points where untrusted data enters the agent's context. - Boundary markers: The fulfillment templates lack explicit boundary markers or instructions to the agent to disregard instructions embedded within the processed data.
- Capability inventory: The skill utilizes shell command execution via Node.js and has the ability to read and write files on the local filesystem.
- Sanitization: There is no evidence of input validation, filtering, or escaping within the provided fulfillment templates to mitigate the risk of malicious data being interpreted as commands.
Audit Metadata