diagram-gen
Pass
Audited by Gen Agent Trust Hub on Mar 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill functions as a standard architectural documentation tool.\n- [DATA_EXFILTRATION]: The skill reads local code snippets and sends them to the OpenAI API for processing. This is a well-known service and the operation is the primary intended function of the skill.\n- [PROMPT_INJECTION]: The tool has an indirect prompt injection surface because it processes untrusted local source files. While malicious instructions in code comments could theoretically influence the diagram generation, the risk is inherent to AI-driven code analysis and the skill implements reasonable data scoping by only reading the start of files.
Audit Metadata