wavedrom-gen

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses fixed versions of official, reputable packages for its core functionality (WaveDrom and resvg).
  • [SAFE]: Local script execution is handled using specific paths relative to the skill directory, avoiding path traversal or arbitrary command execution.
  • [SAFE]: The MCP server registration script includes validation of arguments and proper quoting of command-line parameters to prevent injection.
  • [SAFE]: Data processing logic includes XML and HTML escaping when generating output files, protecting against cross-site scripting (XSS) in the generated HTML previews.
  • [SAFE]: No external network requests or access to sensitive system files were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 01:48 AM
Security Audit — agent-trust-hub — wavedrom-gen