custom-visualization-builder

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the shell tool to scaffold, build, and package visualizations. It includes commands for project initialization via npx, dependency installation via yarn, and application deployment using the Splunk CLI.
  • [EXTERNAL_DOWNLOADS]: The workflow requires downloading developer tools and libraries from public registries. It specifically references official @splunk packages and standard peer dependencies like react.
  • [PROMPT_INJECTION]: The skill manages the processing of untrusted search results within visualizations. It provides specific instructions to developers on safe rendering techniques, such as using textContent to prevent script injection from search field values.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 11:49 PM
Security Audit — agent-trust-hub — custom-visualization-builder