mermaid-tools

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted markdown data which creates a vulnerability surface where malicious code within Mermaid diagrams or section headers could attempt to influence the processing logic.
  • Ingestion points: The main bash script extract-and-generate.sh accepts a user-provided markdown file path as its primary input.
  • Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the processed markdown content.
  • Capability inventory: The skill invokes several subprocesses, including python3, mmdc (which launches a headless browser), and identify from the ImageMagick suite.
  • Sanitization: The Python script extract_diagrams.py uses regular expressions to sanitize headers before using them as filenames, but the core diagram content is passed directly to the mmdc renderer without validation or sanitization.
  • [COMMAND_EXECUTION]: The extract-and-generate.sh script executes multiple system commands to manage directories, process data, and validate generated images, including mkdir, python3, mmdc, stat, and identify.
  • [EXTERNAL_DOWNLOADS]: The documentation in references/setup_and_troubleshooting.md provides commands to fetch the Google Chrome signing key and installation packages from Google's official servers.
  • [PRIVILEGE_ESCALATION]: Setup instructions in the troubleshooting guide include the use of sudo for repository configuration and the installation of system-level packages required for the Chrome browser and its dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:06 AM
Security Audit — agent-trust-hub — mermaid-tools