plantuml-skill
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill employs
curlto interact with rendering APIs and usesgitto perform version checks and updates from its source repository. - [EXTERNAL_DOWNLOADS]: It fetches version information from the official GitHub repository and can download skill updates if the user provides permission. It also refers users to the official PlantUML website to download the library for local use.
- [DATA_EXFILTRATION]: As part of its core functionality, the skill transmits diagram source text to the public Kroki API (
https://kroki.io) for rendering into PNG or SVG formats. This is a standard and expected behavior for the service provided.
Audit Metadata