plantuml
Pass
Audited by Gen Agent Trust Hub on Oct 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on executing external binaries including
java(forplantuml.jar),dot(Graphviz), and theplantumlcommand-line utility. - Evidence in
scripts/convert_puml.py,scripts/check_setup.py, andscripts/resilient_processor.pyshows the use ofsubprocess.runwith arguments passed as a list, which effectively prevents shell injection vulnerabilities. - The commands are used strictly for their intended purpose: environment verification and diagram rendering.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data in the form of PlantUML source code embedded in markdown files or provided as standalone
.pumlfiles. - Ingestion points:
scripts/process_markdown_puml.pyandscripts/resilient_processor.pyread content from user-provided files. - Boundary markers: The skill expects diagrams to be delimited by standard PlantUML tags (
@startuml/@enduml) or markdown code blocks. - Capability inventory: The skill uses the extracted content as input for the PlantUML rendering engine. PlantUML itself supports a
!includedirective which can be used to read local files if not restricted by the Java security policy of the renderer. - Sanitization: The scripts do not perform deep inspection or filtering of the diagram content before passing it to the renderer, relying on the renderer's own constraints.
- [EXTERNAL_DOWNLOADS]: The documentation references several trusted external sources for required prerequisites.
- It directs users to download
plantuml.jarfromplantuml.comandjavafromoracle.comor official open-source registries. - It references documentation and libraries from
github.com/plantumlandraw.githubusercontent.com/plantuml-stdlib.
Audit Metadata