ptlam-mermaiding

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill contains no executable scripts, external dependencies, or network-based operations. It consists purely of markdown guidelines for diagram creation.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection as it processes user-supplied domain evidence to generate diagram source code and has the capability to modify files. However, this risk is mitigated by instructions that mandate manual syntax and meaning verification, along with a strict requirement to obtain user permission before changing any files. Ingestion points: User-supplied domain evidence (SKILL.md, Section 2). Boundary markers: Absent. Capability inventory: File-writing capability (SKILL.md, Intro). Sanitization: Syntax and rendering verification requirements (SKILL.md, Section 5).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 06:26 PM
Security Audit — agent-trust-hub — ptlam-mermaiding