documd-visuals

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation references official software packages hosted on NPM, specifically under the @markdown-viewer scope (e.g., @markdown-viewer/documd, @markdown-viewer/draw-uml) and the well-known @antv/infographic library from Ant Group. These are used for the document conversion and rendering pipeline.
  • [INDIRECT_PROMPT_INJECTION]: As a visualization skill, it creates a surface where the agent populates templates with data from its current session. However, the skill includes 'Iron Rules' that explicitly require data to be inlined rather than loaded from remote URLs, which significantly mitigates risks associated with loading malicious external payloads during the rendering process.
  • [SAFE]: The skill uses an 'assume-safe' configuration for its rendering engines. For instance, the ECharts and Vega documentation specifically note that the input must be pure JSON and that JavaScript function evaluation is disabled. This prevents Cross-Site Scripting (XSS) or arbitrary code execution within the generated visualizations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 02:11 AM
Security Audit — agent-trust-hub — documd-visuals