NYC

scientific-visualization

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [Prompt Injection] (SAFE): No attempts to override agent behavior or bypass safety filters. Instructional language is limited to scientific visualization best practices.
  • [Data Exposure & Exfiltration] (SAFE): No hardcoded credentials, sensitive file paths, or network exfiltration patterns detected. All code is focused on color palette application.
  • [Obfuscation] (SAFE): No use of Base64, zero-width characters, or other encoding techniques to hide malicious intent.
  • [Unverifiable Dependencies & Remote Code Execution] (SAFE): The skill references standard scientific libraries (matplotlib, seaborn, plotly) and does not perform remote script execution or download untrusted packages.
  • [Privilege Escalation] (SAFE): No commands targeting system permissions or administrative access.
  • [Persistence Mechanisms] (SAFE): No modifications to system startup scripts, cron jobs, or registry keys.
  • [Metadata Poisoning] (SAFE): File names and descriptions are accurate and lack deceptive instructions.
  • [Indirect Prompt Injection] (SAFE): The skill does not ingest or process untrusted external data, eliminating the surface for indirect injection attacks.
  • [Time-Delayed / Conditional Attacks] (SAFE): No logic found that gates behavior based on time, date, or specific environment conditions.
  • [Dynamic Execution] (SAFE): No unsafe usage of eval, exec, or runtime code generation. The use of matplotlib's rcParams is standard configuration practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:20 PM