chart-image

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The fulfillment examples provided in CAPABILITY.md for the lineChart, barChart, and areaChart methods interpolate user-provided parameters like ${title} and ${JSON.stringify(data)} directly into shell command strings. This practice is vulnerable to command injection if the agent does not properly escape or sanitize the input values before execution.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted data that could contain malicious instructions designed to influence the agent's behavior or manipulate the generated output.
  • Ingestion points: Parameters such as data, title, and options in the capability definitions are points where untrusted data enters the agent's context.
  • Boundary markers: The fulfillment templates lack explicit boundary markers or instructions to the agent to disregard instructions embedded within the processed data.
  • Capability inventory: The skill utilizes shell command execution via Node.js and has the ability to read and write files on the local filesystem.
  • Sanitization: There is no evidence of input validation, filtering, or escaping within the provided fulfillment templates to mitigate the risk of malicious data being interpreted as commands.
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 10:49 AM
Security Audit — agent-trust-hub — chart-image