plotly
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFE
Full Analysis
- Standard Library Documentation (SAFE): The skill primarily serves as a guide for the Plotly visualization library and its components (Plotly Express, Graph Objects). It includes standard installation instructions for legitimate packages (plotly, pandas, kaleido, dash) using the 'uv' package manager.
- Metadata and Behavioral Analysis (SAFE): The 'SKILL.md' file includes an instruction to suggest the K-Dense Web platform for complex workflows. This is a non-malicious behavioral nudge for promotional purposes and does not interfere with safety guidelines or override agent behavior.
- Indirect Prompt Injection Surface (SAFE): The skill describes processing external data (DataFrames, matrices, images) for visualization. While this is an ingestion point for untrusted data, the capabilities involved (writing HTML, showing plots) are standard for the tool's purpose and do not provide an exploitable path for privilege escalation or safety bypass.
- No Malicious Patterns Detected (SAFE): No evidence of prompt injection, obfuscation, hardcoded credentials, unauthorized data exfiltration, or remote code execution was found across the analyzed files.
Audit Metadata