learn-visual
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied concepts to create SVG files, creating a potential surface for indirect prompt injection where untrusted data could influence generated output. Ingestion points: User concept descriptions and diagram requests via SKILL.md. Boundary markers: None explicitly defined. Capability inventory: File system write access to the
.alvar/visuals/directory. Sanitization: None specified, though instructions require the agent to simplify SVGs for manual auditing. - [SAFE]: No signs of obfuscation, hardcoded credentials, or unauthorized network activity were detected. The skill performs standard file writing operations within a designated directory for educational purposes.
Audit Metadata