obsidian-mermaid-visualizer

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is composed entirely of Markdown documentation and reference files designed to guide an AI agent in generating Mermaid syntax. It does not include any executable scripts (Python, JavaScript, etc.) or binaries.
  • [EXTERNAL_DOWNLOADS]: The structural/architecture.md file identifies a dependency on the Iconify CDN (cdn.jsdelivr.net) for certain icons. This is a well-known service and is correctly documented as a network dependency for the final diagram rendering in the user's environment, rather than a script executed by the agent.
  • [PROMPT_INJECTION]: The instructions in SKILL.md are descriptive and focus on the selection of diagram types based on user intent. There are no patterns suggesting attempts to override system instructions or bypass safety guidelines.
  • [DATA_EXFILTRATION]: No commands for accessing sensitive local file paths (e.g., .ssh, .aws) or performing network requests to unknown domains were found. The skill operates purely on the content provided by the user to generate diagrams.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials, API keys, or secrets are present in any of the skill's files.
  • [COMMAND_EXECUTION]: The skill does not utilize shell commands or perform any operations that could lead to unauthorized command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 05:05 PM
Security Audit — agent-trust-hub — obsidian-mermaid-visualizer