bubble-chart-generator

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill generates HTML templates that reference the Chart.js library via a script tag pointing to https://cdn.jsdelivr.net/npm/chart.js@4.4.0/dist/chart.umd.min.js. JSDelivr is a widely recognized and trusted Content Delivery Network for open-source assets.
  • [INDIRECT_PROMPT_INJECTION]: The skill architecture involves ingesting user-provided data and interpolating it into generated JavaScript code, which represents a vulnerability surface for data poisoning.
  • Ingestion points: The skill collects item names, categories, and numerical values from the user to populate the data array in template-main.html as described in the Workflow (Step 3).
  • Boundary markers: There are no instructions to use delimiters or provided warnings to the agent regarding the handling of potentially malicious instructions embedded within the user's chart data.
  • Capability inventory: The skill is designed to perform file system write operations to create main.html, style.css, and index.md in the docs/sims/ directory.
  • Sanitization: The skill instructions do not specify a requirement to sanitize, escape, or validate the user-provided strings before they are placed into the innerHTML or JavaScript object literals within the generated files.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 06:32 PM