plantuml

Pass

Audited by Gen Agent Trust Hub on Oct 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on executing external binaries including java (for plantuml.jar), dot (Graphviz), and the plantuml command-line utility.
  • Evidence in scripts/convert_puml.py, scripts/check_setup.py, and scripts/resilient_processor.py shows the use of subprocess.run with arguments passed as a list, which effectively prevents shell injection vulnerabilities.
  • The commands are used strictly for their intended purpose: environment verification and diagram rendering.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data in the form of PlantUML source code embedded in markdown files or provided as standalone .puml files.
  • Ingestion points: scripts/process_markdown_puml.py and scripts/resilient_processor.py read content from user-provided files.
  • Boundary markers: The skill expects diagrams to be delimited by standard PlantUML tags (@startuml/@enduml) or markdown code blocks.
  • Capability inventory: The skill uses the extracted content as input for the PlantUML rendering engine. PlantUML itself supports a !include directive which can be used to read local files if not restricted by the Java security policy of the renderer.
  • Sanitization: The scripts do not perform deep inspection or filtering of the diagram content before passing it to the renderer, relying on the renderer's own constraints.
  • [EXTERNAL_DOWNLOADS]: The documentation references several trusted external sources for required prerequisites.
  • It directs users to download plantuml.jar from plantuml.com and java from oracle.com or official open-source registries.
  • It references documentation and libraries from github.com/plantuml and raw.githubusercontent.com/plantuml-stdlib.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 10, 2026, 12:22 AM