space-text-logic-diagram

Pass

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill operates entirely within its intended scope of logical text analysis and SVG generation.
  • [EXTERNAL_DOWNLOADS]: Fetches styling information from Google Fonts (fonts.googleapis.com) to provide the 'JetBrains Mono' font for the generated diagrams. This is a well-known service used for common web assets.
  • [PROMPT_INJECTION]: The skill handles untrusted data which presents an indirect injection surface. 1. Ingestion points: User-provided text, articles, or paragraphs (SKILL.md). 2. Boundary markers: No specific delimiters are defined in the instructions to isolate user input from the HTML/SVG structure. 3. Capability inventory: The skill generates an HTML file containing CSS, SVG, and a theme-switching JavaScript function (template.html). 4. Sanitization: No explicit sanitization or escaping instructions are present for the keyword extraction or concept mapping process. However, the risk is classified as minor given the tool's primary function of static visualization.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 4, 2026, 11:01 AM
Security Audit — agent-trust-hub — space-text-logic-diagram