query-card-visualization

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to utilize a command-line tool named observe to retrieve the latest version of the skill and its reference files. This tool appears to be a legitimate part of the platform's infrastructure, especially as the skill is authored by 'observeinc'.
  • [EXTERNAL_DOWNLOADS]: The JSON schemas included in the references directory point to https://json-schema.org, which is a well-known and trusted service providing standard schema definitions. These references are used for validation purposes and represent safe, standard practice.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the transformation of natural language user requests into structured visualization templates. While this involves processing untrusted user input, the skill provides rigid JSON schemas and instructions to ensure data is correctly shaped and limited to the expected visualization parameters, minimizing the risk of prompt injection through data interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 09:22 PM
Security Audit — agent-trust-hub — query-card-visualization