dashboard-design

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill uses workflow-enforcing language such as "CRITICAL" and "IMPORTANT" to guide the user through a sequential design process. These instructions are benign, intended for task integrity, and do not attempt to bypass safety guidelines.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting untrusted user descriptions and requirements to generate YAML specification files. (1) Ingestion points: User-provided dashboard goals, personas, and data source details defined in the Step 1 workflow. (2) Boundary markers: Absent; there are no specific delimiters to distinguish user content from instructions. (3) Capability inventory: The skill instructs the agent to create and write specification files in the spec/ directory. (4) Sanitization: No explicit validation or escaping of user-provided strings is specified before they are documented in the YAML files.
  • [EXTERNAL_DOWNLOADS]: The skill contains links to the official Vizro documentation hosted on ReadTheDocs, which is a trusted and well-known service for technical documentation.
  • [SAFE]: No sensitive data exposure or hardcoded credentials were identified. Mentions of data sources like PostgreSQL or APIs are illustrative examples used during the requirements gathering phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 08:17 PM