technical-diagram

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local shell script scripts/render_d2.sh to invoke the d2 command-line tool for diagram formatting and rendering.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided technical descriptions to generate D2 source code and SVG files. This creates an attack surface where malicious instructions could be embedded in the input data, potentially influencing the agent's file-writing behavior.
  • [DYNAMIC_EXECUTION]: The rendering script allows specifying the d2 binary path via the D2_BIN environment variable, which is a form of dynamic path execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 04:55 AM
Security Audit — agent-trust-hub — technical-diagram