mermaid-skill

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill makes network requests using curl to an external domain (https://kroki.io) to validate and render Mermaid diagrams when the local compiler option is not utilized.
  • [EXTERNAL_DOWNLOADS]: The documentation instructs the environment to install external packages, specifically @mermaid-js/mermaid-cli via npm and the Chrome headless shell via Puppeteer.
  • [COMMAND_EXECUTION]: The execution workflow triggers local shell commands including mmdc for rendering, sips or file for verifying image outputs, and a local Python script scripts/mermaid_live_link.py to generate sharing links.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:11 PM
Security Audit — agent-trust-hub — mermaid-skill