visualize-arch
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary workflow involves reading and analyzing various files from a software repository to generate architecture diagrams, creating a surface where malicious content within a processed repository could influence the agent's behavior. Ingestion points: The agent is instructed to read repository instructions, architecture documents, entry points, routes, database schemas, and test files in SKILL.md (Step 3: Collect evidence). Boundary markers: No specific delimiters or warnings are used to differentiate untrusted repository content from the agent's internal reasoning or instructions. Capability inventory: The agent can write files and execute the render_tikz.py script which invokes external binaries. Sanitization: No explicit sanitization or validation of the data extracted from the repository is performed before incorporating it into the TeX source.
- [COMMAND_EXECUTION]: The skill includes a Python script (scripts/render_tikz.py) that executes system commands using the subprocess module. The script invokes latexmk and pdftocairo to transform TikZ source files into PDF and SVG outputs. It uses list-based arguments for subprocess.run, which mitigates direct shell injection through the arguments themselves, but relies on the security of the underlying tools.
- [DYNAMIC_EXECUTION]: The workflow requires the compilation of LaTeX/TikZ code generated or modified by the agent based on repository evidence. LaTeX is a powerful, programmable typesetting language; if a malicious actor successfully injects TeX primitives into the diagram source through the indirect injection vector, it could lead to arbitrary command execution depending on the local environment's security configuration.
Audit Metadata