creating-mermaid-diagrams
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
mmdccommand-line tool for validating and exporting diagrams to PNG, SVG, or PDF formats locally. - [EXTERNAL_DOWNLOADS]: The skill uses
curlto interact with the Kroki API athttps://kroki.iofor remote diagram rendering. Kroki is a well-known and established service for this purpose. - [COMMAND_EXECUTION]: Implements a self-update routine using
git ls-remoteto check for new tags andgit pullto update the skill. This process is gated by a 24-hour throttle and requires explicit user consent before any changes are made to the local repository. - [EXTERNAL_DOWNLOADS]: Suggests the installation of
@mermaid-js/mermaid-clifrom the official npm registry as a prerequisite for local rendering. - [INDIRECT_PROMPT_INJECTION]: The skill transforms user-provided prompts into Mermaid diagram code, which is then processed by external tools. This represents a standard data-processing surface. Ingestion points: User diagram descriptions in SKILL.md. Boundary markers: None identified. Capability inventory: Local command execution and network requests via curl. Sanitization: Relies on Mermaid DSL validation steps before export.
Audit Metadata