chart

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data and configuration strings to build HTML chart pages that are rendered by the agent (via Playwright) or viewed by a user. It uses direct string replacement to insert content into templates, lacking sanitization against malicious scripts embedded in the data.
  • Ingestion points: Untrusted data is processed by build_chart, build_chart_custom, and save_data within scripts/build_chart.py.
  • Boundary markers: No boundary markers or instructions are used to distinguish between chart instructions and data content.
  • Capability inventory: The skill possesses file write capabilities (HTML, JSON, Python, PNG), browser execution through Playwright, and a local HTTP server.
  • Sanitization: Input data is not escaped or validated before being interpolated into the HTML/JavaScript templates.
  • [DYNAMIC_EXECUTION]: The save_generate_script function in scripts/build_chart.py creates a generate.py file based on provided script content. This script generation pattern is intended for reproducibility but involves writing executable code based on runtime input.
  • [EXTERNAL_DOWNLOADS]: The chart templates reference the Apache ECharts library hosted on the JSDelivr CDN (cdn.jsdelivr.net). This is a well-known and reputable source for library distribution, making the reference itself benign.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:06 AM
Security Audit — agent-trust-hub — chart