mermaid-visualizer

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown instructions and reference documentation for generating Mermaid diagrams. It does not contain any executable scripts, binary files, or configuration that triggers tool usage.
  • [PROMPT_INJECTION]: No malicious instruction override patterns or safety bypass attempts were detected. The instructions focus purely on diagram syntax and formatting guidelines.
  • [DATA_EXFILTRATION]: The skill does not contain any network operations (e.g., curl, wget, fetch) or access to sensitive file paths (e.g., .ssh, .aws, .env). There is no mechanism for exfiltrating data.
  • [COMMAND_EXECUTION]: No shell commands, subprocess calls, or system interactions were identified. The skill's workflow is limited to generating Markdown-compatible Mermaid code.
  • [REMOTE_CODE_EXECUTION]: The skill does not download external scripts, install packages (npm/pip), or execute remote code. All logic is contained within the provided Markdown files.
  • [OBFUSCATION]: Analysis of the text and syntax rules revealed no hidden content, Base64-encoded commands, zero-width characters, or homoglyph-based evasion techniques.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes user-supplied text to generate diagrams, it possesses no exploitable capabilities (such as file writing or network access). The risk is safely managed as the output is restricted to plain-text diagram code.
  • Ingestion points: User-provided text concepts in SKILL.md workflow.
  • Boundary markers: The workflow instructions implicitly define the input as data to be analyzed, though explicit delimiters are not enforced.
  • Capability inventory: None. The skill only outputs text.
  • Sanitization: Includes specific rules to prevent Mermaid syntax errors, which acts as a form of output sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — mermaid-visualizer