math-function-plotter-plotly

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied mathematical functions and interpolates them into a JavaScript file (script.js), creating a potential injection vector if the input is not strictly a mathematical expression.
  • Ingestion points: The skill collects a "Function expression" from the user in SKILL.md (Step 1).
  • Boundary markers: The instructions lack explicit boundary markers or directions for the agent to ignore instructions embedded within the mathematical expression input.
  • Capability inventory: The skill performs file writing (SKILL.md Step 2) and generates executable JavaScript logic (SKILL.md Step 5).
  • Sanitization: No explicit sanitization, validation, or filtering instructions are provided to ensure the user input contains only safe mathematical operations.
  • [DYNAMIC_EXECUTION]: The skill generates a functional JavaScript file (script.js) at runtime by populating the {{FUNCTION_JS}} placeholder in a template (assets/template-script.js) with generated code.
  • [EXTERNAL_DOWNLOADS]: The skill generates HTML that fetches the Plotly.js library from an external Content Delivery Network (CDN).
  • Evidence: assets/template-iframe-main.html includes a script tag pointing to https://cdn.plot.ly/plotly-2.27.0.min.js. This is a well-known service for interactive data visualization.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 06:32 PM