diagram-to-image

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill transmits diagram and table content to an external API (https://diagramless.xyz/api/render) using the Node.js fetch API. While this is the intended functionality for rendering, it involves sending user-provided data to a third-party domain.
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute bundled Node.js and Python scripts (diagram-to-image.mjs, table_to_image.py) to process data and interact with the file system. These operations include reading from temporary files and writing PNG images to various project directories.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-supplied diagrams and tables as input for the rendering scripts. The ingestion of this data without specific sanitization represents a potential surface for indirect injection, although the impact is limited by the skill's restricted output format (static images).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:34 AM
Security Audit — agent-trust-hub — diagram-to-image