uml-and-software-architecture-visualization

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill processes external data formats such as XMI, SQL schemas, and specialized DSLs which could potentially contain embedded instructions intended to influence agent behavior.
  • Ingestion points: Processes XMI, UMLDI, SQL schemas, and various DSLs (PlantUML, Mermaid, D2) as noted in SKILL.md and references/formats-and-interchange.md.
  • Boundary markers: The skill does not explicitly specify delimiters for all inputs but emphasizes semantic and quality checks in references/quality-accessibility-export-testing.md to validate model integrity.
  • Capability inventory: Involves subprocess calls for rendering tools and file system access for source management as described in references/typescript-web-rendering.md.
  • Sanitization: Relies on internal agent safety filters and the specific semantic parsing of the diagramming tools to mitigate risks associated with untrusted data.
  • [Standard Visualization Tooling]: The skill recommends the use of well-established visualization libraries and tools (e.g., Mermaid, React Flow, Cytoscape.js). These are industry standards and are referenced here for their intended documentation and rendering capabilities.
  • [Rendering Workflow]: The workflow describes the use of rendering engines and potential external services to convert text-based descriptions into visual diagrams. This represents a standard architectural pattern for diagram-as-code implementations and is documented with appropriate usage context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 10:21 AM
Security Audit — agent-trust-hub — uml-and-software-architecture-visualization