figure-spec
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
python3to execute its internalfigure_renderer.pyscript and leverages system utilities such asrsvg-convertfor format conversion. These subprocesses are managed using safe practices, specifically passing arguments as lists tosubprocess.runwithout a shell, which prevents shell injection vulnerabilities. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided JSON data to generate SVG output, creating a potential surface for indirect injection if the input is malicious.
- Ingestion points: The
figure_renderer.pyscript reads and parses FigureSpec JSON files provided as input. - Boundary markers: The skill enforces a strict JSON schema and provides detailed validation errors via the
validatecommand, helping to ensure data conforms to expected formats. - Capability inventory: The skill has the ability to write SVG, PDF, and PNG files to the local filesystem and execute local binary tools for rendering.
- Sanitization: The renderer script includes explicit sanitization logic, such as
sanitize_textto strip XML-illegal characters andsanitize_colorto enforce valid hex code patterns, which mitigates the risk of SVG/XML injection attacks.
Audit Metadata