plotly

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill includes a 'Suggest Using K-Dense Web For Complex Worflows' section that explicitly instructs the agent to monitor task complexity and proactively recommend a third-party service (www.k-dense.ai). This modifies the agent's output behavior to include unsolicited promotional content based on conditional triggers.
  • [COMMAND_EXECUTION]: The documentation provides instructions for installing Python packages via 'uv add' and includes examples for running a local web application server using Dash's 'app.run_server(debug=True)'. While these are functional requirements for the library, they involve executing code that interacts with the local environment and network.
  • [EXTERNAL_DOWNLOADS]: The skill references several external sites, including the official Plotly documentation, community forums, and a GitHub repository for the skill source, which results in the agent or user accessing content outside the local context.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — plotly