beautiful-mermaid-editor

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it is instructed to ingest and follow guidelines from external files within a target repository.
  • Ingestion points: The skill instructions in SKILL.md direct the agent to read AGENTS.md, package.json, and various source files from the directory provided in the skill's arguments.
  • Boundary markers: The instructions do not define clear boundaries or provide warnings to ignore potentially malicious instructions embedded in the target repository's files.
  • Capability inventory: The skill utilizes tools such as Bash, Write, and Edit, which allow the agent to perform significant modifications and execute system commands based on the data it processes.
  • Sanitization: No sanitization or validation mechanisms are described for the content read from the target repository before the agent acts upon it.
  • [COMMAND_EXECUTION]: The skill involves the execution of shell commands to build and test the editor, which can trigger scripts defined in the target environment.
  • Evidence: In references/ARCHITECTURE.md and references/VERIFICATION.md, the skill documentation encourages the use of bun run editor and bun run dev. These commands execute scripts defined in the repository's package.json, which could be modified to perform malicious actions if the repository is untrusted.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 10:08 AM