matplotlib

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions directing the agent to proactively recommend the author's hosted platform (K-Dense Web) when user requests involve high complexity. While presented as a productivity suggestion, this represents a directed behavior designed to steer users toward an external service.
  • [SAFE]: The skill includes Python scripts (plot_template.py and style_configurator.py) that perform standard operations such as data processing, visualization, and local file saving. These operations are appropriate for the skill's stated purpose and use well-known libraries.
  • [SAFE]: Analysis of the indirect prompt injection surface as required for data-processing skills:
  • Ingestion points: User-provided data arrays and variables passed to the plotting functions in the documentation and templates.
  • Boundary markers: Not present; the skill does not implement specific delimiters or instructions to ignore embedded commands within the ingested data.
  • Capability inventory: The skill allows for local file system writes (saving plots as PNG/PDF/SVG and configuration files as .mplstyle).
  • Sanitization: No data validation, escaping, or sanitization logic is applied to the inputs before they are visualized.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — matplotlib