skills/jeremylongshore/claude-code-plugins-plus-skills/mermaid-er-diagram-creator/Gen Agent Trust Hub
mermaid-er-diagram-creator
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [Indirect Prompt Injection] (LOW): The skill structure includes a vulnerability surface for indirect prompt injection.
- Ingestion points: Processes external data via the
ReadandEdittools specified inSKILL.md. - Boundary markers: No explicit delimiters or instructions are present to differentiate between user data and system instructions.
- Capability inventory: The agent is granted the
Bash,Grep,Write, andEdittools, providing significant system access. - Sanitization: The skill definition lacks any input validation or sanitization mechanisms to filter malicious content within diagram data.
Audit Metadata