plantuml
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill extracts untrusted data from the interaction context to generate PlantUML source code for rendering. Ingestion points: interaction context referenced in SKILL.md. Boundary markers: absent. Capability inventory: bash tool for file writing and executing plantuml. Sanitization: absent.
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute system commands to interact with the local environment. Evidence includes the use of emacsclient to query face colors and plantuml to render PNG images from generated source files.
Audit Metadata