SPACE-analytics

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the Chart.js and D3.js libraries fetched from Cloudflare's cdnjs repository in the assets/report-template.html file to provide interactive data visualizations.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core function of processing untrusted external data. * Ingestion points: User-provided CSV, Excel, and SQL query results as described in SKILL.md. * Boundary markers: There are no explicit instructions to the agent to disregard instructions potentially embedded within the data content. * Capability inventory: The skill is limited to generating HTML/JS report content; it does not request tools for persistent file modifications or arbitrary network communication. * Sanitization: The instructions do not define methods for sanitizing or validating the contents of the processed data files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 09:12 AM