mermaidjs-v11

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS] (SAFE): The skill correctly references official packages from the @mermaid-js scope on npm and utilizes trusted CDNs like jsDelivr and esm.run for asset delivery. These are industry-standard practices for this type of tool.
  • [COMMAND_EXECUTION] (SAFE): The command-line interface (CLI) examples for 'mmdc' are legitimate and intended for the primary purpose of the skill (rendering diagrams). The provided Docker instructions include best practices like matching host user IDs to prevent permission issues.
  • [DATA_EXFILTRATION] (SAFE): No evidence of hardcoded credentials, access to sensitive system files, or unauthorized network activity was found.
  • [PROMPT_INJECTION] (SAFE): The skill content is focused on technical documentation and does not contain any adversarial instructions aimed at bypassing AI safety protocols or overriding system prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 04:58 PM