mermaid-sop-check
Pass
Audited by Gen Agent Trust Hub on Mar 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@mermaid-js/mermaid-clipackage via npm. This is the official command-line interface for Mermaid, a widely recognized and trusted open-source project. - [COMMAND_EXECUTION]: The skill provides instructions to run the
mmdcexecutable. These commands are limited to syntax validation and image rendering for Mermaid files, utilizing standard flags and local file paths without requesting elevated privileges. - [PROMPT_INJECTION]: No evidence of prompt injection, instruction overrides, or attempts to bypass AI safety guidelines was found in the text or metadata.
- [DATA_EXPOSURE]: The script uses the
/tmp/directory for temporary output files, which is a standard practice and does not involve accessing sensitive user data or hardcoded credentials.
Audit Metadata