whirlybird

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a structural assistant, transforming text into Mermaid mindmap syntax. It does not employ tools for network access, file manipulation, or command execution.
  • [SAFE]: Security analysis of all skill files and references found no malicious patterns, prompt injections, or obfuscated content.
  • [INDIRECT_PROMPT_INJECTION]: The skill is intended to process external 'Madman' text input. While this represents a data ingestion surface, the risk is deemed safe due to the skill's output being limited to textual diagram code, preventing the execution of malicious instructions. Evidence: (1) Ingestion points: SKILL.md (Core Workflow); (2) Boundary markers: Not defined; (3) Capability inventory: Mermaid generation; (4) Sanitization: Not performed on inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 12:42 AM
Security Audit — agent-trust-hub — whirlybird