fireworks-tech-graph
Pass
Audited by Gen Agent Trust Hub on Jul 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified. The skill is purely functional, providing templates and automation for creating system architectures and UML diagrams.
- [COMMAND_EXECUTION]: The skill uses local shell scripts (
validate-svg.sh,generate-diagram.sh) and a Python script (generate-from-template.py) to automate diagram creation and validation. These scripts are benign and use standard system utilities likersvg-convert(part of the well-knownlibrsvglibrary) andxmllint. - [DATA_EXFILTRATION]: No network operations or credential harvesting patterns were detected. The skill operates entirely on local files to generate and export visual assets.
- [PROMPT_INJECTION]: The instructions in
SKILL.mdare focused on diagramming logic and layout rules. There are no attempts to bypass safety filters or override agent constraints. - [REMOTE_CODE_EXECUTION]: The skill does not download or execute remote code. It relies on locally installed tools (
librsvg) and standard Python libraries for its functionality. - [INDIRECT_PROMPT_INJECTION]: While the skill processes untrusted user input to generate diagram text, the
generate-from-template.pyscript correctly usesxml.sax.saxutils.escapeto sanitize text content before inserting it into SVG templates, mitigating XML injection risks.
Audit Metadata