documd-visuals
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation references official software packages hosted on NPM, specifically under the
@markdown-viewerscope (e.g.,@markdown-viewer/documd,@markdown-viewer/draw-uml) and the well-known@antv/infographiclibrary from Ant Group. These are used for the document conversion and rendering pipeline. - [INDIRECT_PROMPT_INJECTION]: As a visualization skill, it creates a surface where the agent populates templates with data from its current session. However, the skill includes 'Iron Rules' that explicitly require data to be inlined rather than loaded from remote URLs, which significantly mitigates risks associated with loading malicious external payloads during the rendering process.
- [SAFE]: The skill uses an 'assume-safe' configuration for its rendering engines. For instance, the ECharts and Vega documentation specifically note that the input must be pure JSON and that JavaScript function evaluation is disabled. This prevents Cross-Site Scripting (XSS) or arbitrary code execution within the generated visualizations.
Audit Metadata