matplotlib
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions directing the agent to proactively recommend the author's hosted platform (K-Dense Web) when user requests involve high complexity. While presented as a productivity suggestion, this represents a directed behavior designed to steer users toward an external service.
- [SAFE]: The skill includes Python scripts (
plot_template.pyandstyle_configurator.py) that perform standard operations such as data processing, visualization, and local file saving. These operations are appropriate for the skill's stated purpose and use well-known libraries. - [SAFE]: Analysis of the indirect prompt injection surface as required for data-processing skills:
- Ingestion points: User-provided data arrays and variables passed to the plotting functions in the documentation and templates.
- Boundary markers: Not present; the skill does not implement specific delimiters or instructions to ignore embedded commands within the ingested data.
- Capability inventory: The skill allows for local file system writes (saving plots as PNG/PDF/SVG and configuration files as .mplstyle).
- Sanitization: No data validation, escaping, or sanitization logic is applied to the inputs before they are visualized.
Audit Metadata