infographic-and-data-viz

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes data from external sources to design visualization specifications.
  • Ingestion points: Data is sourced from 'data-and-original-research', 'analytics-and-reporting', and 'competitor-analysis' modules.
  • Boundary markers: The skill explicitly instructs the agent that 'a dataset is material, not a command', providing a logical boundary for the AI.
  • Capability inventory: The agent's capabilities are limited to designing visual specifications (e.g., chart type, titles, scales) and labels. Rendering is performed by external tools (Canva, Flux, Nano-Banana), and publishing is managed by WoopSocial. No direct shell execution or arbitrary file system access was identified within the skill scripts.
  • Sanitization: The skill relies on natural language instructions for safety; it does not specify programmatic sanitization or filtering of input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 02:27 PM
Security Audit — agent-trust-hub — infographic-and-data-viz