figure-spec

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses python3 to execute its internal figure_renderer.py script and leverages system utilities such as rsvg-convert for format conversion. These subprocesses are managed using safe practices, specifically passing arguments as lists to subprocess.run without a shell, which prevents shell injection vulnerabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided JSON data to generate SVG output, creating a potential surface for indirect injection if the input is malicious.
  • Ingestion points: The figure_renderer.py script reads and parses FigureSpec JSON files provided as input.
  • Boundary markers: The skill enforces a strict JSON schema and provides detailed validation errors via the validate command, helping to ensure data conforms to expected formats.
  • Capability inventory: The skill has the ability to write SVG, PDF, and PNG files to the local filesystem and execute local binary tools for rendering.
  • Sanitization: The renderer script includes explicit sanitization logic, such as sanitize_text to strip XML-illegal characters and sanitize_color to enforce valid hex code patterns, which mitigates the risk of SVG/XML injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:08 PM
Security Audit — agent-trust-hub — figure-spec