mermaidjs-v11

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references official Mermaid.js resources, including the @mermaid-js/mermaid-cli package via npm and the mermaid-cli Docker image from the GitHub Container Registry. It also utilizes standard Content Delivery Networks (CDNs) such as jsDelivr and esm.run to load the Mermaid library and icon packs, and mentions the well-known mermaid.ink service for remote rendering.
  • [COMMAND_EXECUTION]: The documentation provides instructions for using the mmdc command-line tool to convert Mermaid diagram files into image formats like SVG, PNG, and PDF. These are standard operations for the tool's intended purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as an interface for rendering Mermaid diagrams from text input. 1. Ingestion points: Mermaid syntax in markdown code blocks. 2. Boundary markers: Markdown code block fences. 3. Capability inventory: Rendering to SVG/PNG/PDF via CLI or DOM via JS API. 4. Sanitization: Built-in DOMPurify and configurable securityLevel ('strict' recommended). While this involves processing untrusted data, the documentation explicitly recommends using the strict security level and mentions built-in XSS protection via DOMPurify to mitigate potential injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:15 AM
Security Audit — agent-trust-hub — mermaidjs-v11