plantuml-skill
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [DATA_EXFILTRATION]: The skill sends diagram source code to the public Kroki API (
https://kroki.io) viacurlPOST requests. This behavior is the default rendering method and is clearly documented. The skill includes explicit warnings about sending sensitive data to the public service and provides instructions for using local Docker or Java backends to keep data within the local environment. - [INDIRECT_PROMPT_INJECTION]: The skill processes external source code and Markdown files to generate diagrams. This ingestion of untrusted data represents an attack surface where malicious input could attempt to influence the agent's output. The risk is managed by instructions directing the agent to extract specific structural entities rather than executing the content.
- [COMMAND_EXECUTION]: The skill uses
curlfor API communication and suggestsdockerorjavafor local rendering. These commands are integral to the skill's stated purpose and are documented for user transparency. - [EXTERNAL_DOWNLOADS]: The skill references and downloads components from well-known external sources such as the Kroki API, the PlantUML website, and GitHub. These references are used for rendering and installation and are clearly identified in the documentation.
Audit Metadata