svg-diagram

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code constitutes a purpose-appropriate tool for generating SVGs from Mermaid diagrams and for creating custom SVGs directly when needed. The footprint is coherent with its stated functionality. However, there are multiple supply-chain and execution-trust considerations: reliance on external tooling (Mermaid CLI via npx without pinning), runtime shell execution, and remote font resources. These patterns warrant caution in high-assurance environments, and they contribute to a moderate security risk profile. Overall, the skill appears benign for legitimate use, but classify as SUSPICIOUS to MEDIUM risk due to potential download/execute patterns and external resource fetches in the data flow. No explicit malicious behavior is evident in the provided fragment, but the design choices (unversioned CLI, /tmp usage, remote font imports) should be documented and limited to trusted environments.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 03:42 PM
Package URL
pkg:socket/skills-sh/modu-ai%2Fsmart-cowork-life%2Fsvg-diagram%2F@2f6f1196299ff5237b6ca5e0e1f76c57886f5505