mathodology-figure-presets

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a library of plotting functions and a generation script that operate on local data using standard, well-maintained scientific libraries. No suspicious behaviors, unauthorized access patterns, or malicious persistence mechanisms were detected.
  • [EXTERNAL_DOWNLOADS]: The manifest file references/sources.tsv records assets downloaded from trusted organizations and well-known services, specifically PLOS journals and the official Matplotlib GitHub repository. These are identified as static reference materials and are not executed as remote code.
  • [CREDENTIALS_UNSAFE]: The skill exhibits safe credential management practices by explicitly instructing the agent not to collect or prompt for API keys in chat sessions when discussing image generation tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (such as CSV files) to generate visualizations. It mitigates potential injection risks by enforcing that all quantitative outputs remain strictly data-driven and advising the agent to verify AI-assisted visual concepts against the source evidence. The assessed severity for this capability surface is low.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:41 AM
Security Audit — agent-trust-hub — mathodology-figure-presets