creating-mermaid-diagrams

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the mmdc command-line tool for validating and exporting diagrams to PNG, SVG, or PDF formats locally.
  • [EXTERNAL_DOWNLOADS]: The skill uses curl to interact with the Kroki API at https://kroki.io for remote diagram rendering. Kroki is a well-known and established service for this purpose.
  • [COMMAND_EXECUTION]: Implements a self-update routine using git ls-remote to check for new tags and git pull to update the skill. This process is gated by a 24-hour throttle and requires explicit user consent before any changes are made to the local repository.
  • [EXTERNAL_DOWNLOADS]: Suggests the installation of @mermaid-js/mermaid-cli from the official npm registry as a prerequisite for local rendering.
  • [INDIRECT_PROMPT_INJECTION]: The skill transforms user-provided prompts into Mermaid diagram code, which is then processed by external tools. This represents a standard data-processing surface. Ingestion points: User diagram descriptions in SKILL.md. Boundary markers: None identified. Capability inventory: Local command execution and network requests via curl. Sanitization: Relies on Mermaid DSL validation steps before export.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — creating-mermaid-diagrams