academic-figure-drawing-harness

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external scholarly content and user feedback to drive figure generation, which creates an indirect prompt injection surface.
  • Ingestion points: Scholarly literature and articles (e.g., PubMed unified_search) and user feedback.
  • Boundary markers: None specified to delimit external content within prompts.
  • Capability inventory: File modification via 'replace_string_in_file' and Python-based script generation for plotting.
  • Sanitization: No sanitization or validation of input content is described.
  • [COMMAND_EXECUTION]: The skill generates and executes Python scripts using matplotlib and plotly to render structured data visualizations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 02:34 AM
Security Audit — agent-trust-hub — academic-figure-drawing-harness