infographic-and-data-viz
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes data from external sources to design visualization specifications.
- Ingestion points: Data is sourced from 'data-and-original-research', 'analytics-and-reporting', and 'competitor-analysis' modules.
- Boundary markers: The skill explicitly instructs the agent that 'a dataset is material, not a command', providing a logical boundary for the AI.
- Capability inventory: The agent's capabilities are limited to designing visual specifications (e.g., chart type, titles, scales) and labels. Rendering is performed by external tools (Canva, Flux, Nano-Banana), and publishing is managed by WoopSocial. No direct shell execution or arbitrary file system access was identified within the skill scripts.
- Sanitization: The skill relies on natural language instructions for safety; it does not specify programmatic sanitization or filtering of input data.
Audit Metadata