skills/shyxin/skills/tui-diagram/Gen Agent Trust Hub

tui-diagram

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process conversation history and save derived content to a local file, presenting a potential vulnerability surface.
  • Ingestion points: The agent is instructed to analyze the "current conversation context" to determine the content and type of the diagram to be drawn.
  • Boundary markers: The instructions do not define boundary markers (such as delimiters) or specific instructions to ignore malicious commands that might be embedded in the conversation context being analyzed.
  • Capability inventory: The skill explicitly authorizes the agent to write and append content to a file named diagrams.md located in the root of the working directory.
  • Sanitization: While the content is intended to be formatted as Unicode characters or Mermaid code blocks, there are no instructions to sanitize or filter the input from the conversation context before writing it to the file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:53 PM
Security Audit — agent-trust-hub — tui-diagram