mermaid-to-proverif

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill facilitates defensive security analysis by generating formal verification models. It incorporates best practices, such as requiring reachability queries (Step 5) to ensure models are structurally sound before security properties are checked.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted Mermaid diagrams to produce ProVerif (.pv) files. While this creates an attack surface where malicious instructions could be embedded in the input diagram to influence the output, the skill mitigates this by providing a highly specific, rule-based translation logic across eight distinct steps. This structured transformation process limits the ability of external data to execute arbitrary commands or override agent behavior.
  • [SAFE]: No obfuscation, hidden URLs, or suspicious encoding techniques were found. All references, examples, and assets originate from the vendor's own infrastructure (Trail of Bits).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:16 PM
Security Audit — agent-trust-hub — mermaid-to-proverif