mermaid-visualizer

Pass

Audited by Gen Agent Trust Hub on Feb 15, 2026

Risk Level: LOWNO_CODE
Full Analysis
  • SAFE (SAFE): Comprehensive analysis of the provided markdown and configuration files reveals no malicious patterns. There are no attempts at prompt injection, obfuscation, or credential theft.
  • NO_CODE (LOW): This skill consists entirely of instructional markdown and reference files. The absence of scripts (Python, Node.js, Shell) or binaries eliminates the risk of Remote Code Execution (RCE) or local command execution.
  • DATA_EXFILTRATION (SAFE): No network functions (e.g., curl, fetch) or sensitive file path references were detected. The skill operates purely on data provided within the agent's context.
  • INDIRECT_PROMPT_INJECTION (INFO): While the skill's purpose is to process external text content for visualization, it lacks any side-effect capabilities (such as writing to files or sending network requests). The attack surface is classified as Tier: INFO, representing negligible risk.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 15, 2026, 08:44 PM