create-gsn-diagram

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes subprocess.run to call a local utility script (memory/run.sh) for data retrieval. This is a standard and secure mechanism for inter-skill communication in this environment, using list-based arguments to prevent shell injection.
  • [EXTERNAL_DOWNLOADS]: The skill specifies well-known dependencies (httpx and graphviz) in its pyproject.toml file. These are official, reputable packages from the Python Package Index (PyPI) used for their intended purposes.
  • [DATA_EXFILTRATION]: The skill processes compliance data to generate human-readable and machine-readable exports (SVG, XML, DOT). Data access is mediated through a local memory service, and there is no evidence of unauthorized network transmission or secret exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — create-gsn-diagram