mermaid-tools
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted markdown data which creates a vulnerability surface where malicious code within Mermaid diagrams or section headers could attempt to influence the processing logic.
- Ingestion points: The main bash script
extract-and-generate.shaccepts a user-provided markdown file path as its primary input. - Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the processed markdown content.
- Capability inventory: The skill invokes several subprocesses, including
python3,mmdc(which launches a headless browser), andidentifyfrom the ImageMagick suite. - Sanitization: The Python script
extract_diagrams.pyuses regular expressions to sanitize headers before using them as filenames, but the core diagram content is passed directly to themmdcrenderer without validation or sanitization. - [COMMAND_EXECUTION]: The
extract-and-generate.shscript executes multiple system commands to manage directories, process data, and validate generated images, includingmkdir,python3,mmdc,stat, andidentify. - [EXTERNAL_DOWNLOADS]: The documentation in
references/setup_and_troubleshooting.mdprovides commands to fetch the Google Chrome signing key and installation packages from Google's official servers. - [PRIVILEGE_ESCALATION]: Setup instructions in the troubleshooting guide include the use of
sudofor repository configuration and the installation of system-level packages required for the Chrome browser and its dependencies.
Audit Metadata