bubble-chart-generator
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill generates HTML templates that reference the Chart.js library via a script tag pointing to
https://cdn.jsdelivr.net/npm/chart.js@4.4.0/dist/chart.umd.min.js. JSDelivr is a widely recognized and trusted Content Delivery Network for open-source assets. - [INDIRECT_PROMPT_INJECTION]: The skill architecture involves ingesting user-provided data and interpolating it into generated JavaScript code, which represents a vulnerability surface for data poisoning.
- Ingestion points: The skill collects item names, categories, and numerical values from the user to populate the
dataarray intemplate-main.htmlas described in the Workflow (Step 3). - Boundary markers: There are no instructions to use delimiters or provided warnings to the agent regarding the handling of potentially malicious instructions embedded within the user's chart data.
- Capability inventory: The skill is designed to perform file system write operations to create
main.html,style.css, andindex.mdin thedocs/sims/directory. - Sanitization: The skill instructions do not specify a requirement to sanitize, escape, or validate the user-provided strings before they are placed into the
innerHTMLor JavaScript object literals within the generated files.
Audit Metadata