fireworks-tech-graph

Pass

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified. The skill is purely functional, providing templates and automation for creating system architectures and UML diagrams.
  • [COMMAND_EXECUTION]: The skill uses local shell scripts (validate-svg.sh, generate-diagram.sh) and a Python script (generate-from-template.py) to automate diagram creation and validation. These scripts are benign and use standard system utilities like rsvg-convert (part of the well-known librsvg library) and xmllint.
  • [DATA_EXFILTRATION]: No network operations or credential harvesting patterns were detected. The skill operates entirely on local files to generate and export visual assets.
  • [PROMPT_INJECTION]: The instructions in SKILL.md are focused on diagramming logic and layout rules. There are no attempts to bypass safety filters or override agent constraints.
  • [REMOTE_CODE_EXECUTION]: The skill does not download or execute remote code. It relies on locally installed tools (librsvg) and standard Python libraries for its functionality.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes untrusted user input to generate diagram text, the generate-from-template.py script correctly uses xml.sax.saxutils.escape to sanitize text content before inserting it into SVG templates, mitigating XML injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 4, 2026, 04:36 PM
Security Audit — agent-trust-hub — fireworks-tech-graph