mermaid-diagram
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill attempts to use
npx -y @mermaid-js/mermaid-cli@latestto verify diagram syntax if a local installation is not found. This pattern downloads and executes code from the public NPM registry at runtime. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided requirements through the
$ARGUMENTSvariable to generate diagrams. It lacks explicit boundary markers or instructions to ignore potential commands embedded within the user's diagram description. - Ingestion points: User requirements provided via
$ARGUMENTSinSKILL.md. - Boundary markers: None identified; user input is parsed directly in Step 1.
- Capability inventory: The skill has access to shell execution (Bash), file system operations (Read, Write, Edit, Glob, Grep), and directory management.
- Sanitization: No input sanitization or validation of the
$ARGUMENTScontent is performed before processing. - [COMMAND_EXECUTION]: The workflow involves executing shell commands to create the
figures/directory (mkdir) and run the Mermaid compiler (mmdc) to render diagrams to PNG for visual verification.
Audit Metadata