pma-d2
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
references/render.mdandreferences/integration.mdfiles contain instructions for users to install the D2 CLI using an official shell script (e.g.,curl -fsSL https://d2lang.com/install.sh | sh -s --). These are provided as documentation and are not executed by the agent. - [EXTERNAL_DOWNLOADS]: The skill references several well-known icon and image repositories, including
icons.terrastruct.com,svgrepo.com, andsimpleicons.org, to be used as assets within generated diagrams. - [SAFE]: The main skill definition (SKILL.md) establishes strict rules that the agent's output must be limited to
.d2text and that it must never invoke a renderer or execute system commands. This design significantly minimizes the skill's attack surface.
Audit Metadata