mermaid-graph-writer
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious behavior, obfuscation, or unauthorized data access patterns were identified. The instructions focus entirely on Mermaid diagram syntax and best practices. The provided Python script,
scripts/validate_mermaid.py, is a standard utility that performs static syntax analysis and does not involve any network activity, privilege escalation, or dynamic code execution. - [INDIRECT_PROMPT_INJECTION]: The skill operates by transforming user-supplied descriptions and file content into Mermaid diagrams using file system tools (
Read,Write,Edit). This represents an indirect prompt injection surface if the inputs originate from untrusted sources. However, this risk is inherent to the skill's primary function and is mitigated by the structured nature of the Mermaid DSL output. - Ingestion points: User-provided descriptions and file content read via the
Readtool. - Boundary markers: Absent from the instructions.
- Capability inventory:
Read,Write, andEdittools; local syntax validation viascripts/validate_mermaid.py. - Sanitization: Not explicitly defined in the instructions.
Audit Metadata