diagram-generator
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes user-controlled text within its prompt generation logic without adequate isolation.
- Ingestion points: The
topiccommand-line argument inscripts/generate_diagram.pyserves as the entry point for untrusted user data. - Boundary markers: Absent. The user input is interpolated directly into the
meta_promptstring using f-strings without the use of delimiters (like XML tags or triple quotes) or instructions to ignore embedded commands. - Capability inventory: The skill possesses the capability to write files to the local filesystem using the
Pillowlibrary'ssavemethod inscripts/generate_diagram.py. - Sanitization: Absent. No validation, escaping, or filtering is applied to the user-supplied topic before it is included in the prompt sent to the Gemini API.
Audit Metadata