mermaidjs-v11
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references official Mermaid.js resources, including the
@mermaid-js/mermaid-clipackage via npm and themermaid-cliDocker image from the GitHub Container Registry. It also utilizes standard Content Delivery Networks (CDNs) such as jsDelivr and esm.run to load the Mermaid library and icon packs, and mentions the well-knownmermaid.inkservice for remote rendering. - [COMMAND_EXECUTION]: The documentation provides instructions for using the
mmdccommand-line tool to convert Mermaid diagram files into image formats like SVG, PNG, and PDF. These are standard operations for the tool's intended purpose. - [INDIRECT_PROMPT_INJECTION]: The skill acts as an interface for rendering Mermaid diagrams from text input. 1. Ingestion points: Mermaid syntax in markdown code blocks. 2. Boundary markers: Markdown code block fences. 3. Capability inventory: Rendering to SVG/PNG/PDF via CLI or DOM via JS API. 4. Sanitization: Built-in DOMPurify and configurable
securityLevel('strict' recommended). While this involves processing untrusted data, the documentation explicitly recommends using thestrictsecurity level and mentions built-in XSS protection via DOMPurify to mitigate potential injection risks.
Audit Metadata