research-to-diagram

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard Graphviz dot commands to compile diagram files into PDF, PNG, or SVG formats. It also includes a shell script (scripts/generate_pdf.sh) to automate this process. These are legitimate uses within the skill's stated purpose of visualization.
  • [EXTERNAL_DOWNLOADS]: The documentation mentions installing Graphviz via official system package managers (brew install graphviz, apt-get install graphviz). These are well-known, trusted package registries and represent safe, standard installation practices.
  • [PROMPT_INJECTION]: No malicious prompt injection patterns, role-play bypasses, or instructions to ignore safety guidelines were found in the skill metadata or instructions.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data access, credential harvesting, or network operations to untrusted domains was found. The skill uses the internal WebSearch tool for its intended research purpose.
  • [OBFUSCATION]: The skill uses clear text throughout all files. No Base64, hex encoding, zero-width characters, or other obfuscation techniques were detected.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes data from the web via WebSearch, it is intended to summarize and visualize information. The risk is considered low as the platform's standard guardrails apply to the search tool's output.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 05:41 PM
Security Audit — agent-trust-hub — research-to-diagram