dashboard-design
Pass
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill uses workflow-enforcing language such as "CRITICAL" and "IMPORTANT" to guide the user through a sequential design process. These instructions are benign, intended for task integrity, and do not attempt to bypass safety guidelines.
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting untrusted user descriptions and requirements to generate YAML specification files. (1) Ingestion points: User-provided dashboard goals, personas, and data source details defined in the Step 1 workflow. (2) Boundary markers: Absent; there are no specific delimiters to distinguish user content from instructions. (3) Capability inventory: The skill instructs the agent to create and write specification files in the spec/ directory. (4) Sanitization: No explicit validation or escaping of user-provided strings is specified before they are documented in the YAML files.
- [EXTERNAL_DOWNLOADS]: The skill contains links to the official Vizro documentation hosted on ReadTheDocs, which is a trusted and well-known service for technical documentation.
- [SAFE]: No sensitive data exposure or hardcoded credentials were identified. Mentions of data sources like PostgreSQL or APIs are illustrative examples used during the requirements gathering phase.
Audit Metadata