Back to skill

Security audit

Mermaid Charts 全图表画图技能

Security checks for vulnerabilities and agentic risk

Overview

This Mermaid diagram skill is purpose-aligned and low risk, with one caution that its HTML example loads Mermaid JavaScript from a public CDN.

Installers should be comfortable with a Mermaid documentation skill that may guide agents to run mmdc locally. For sensitive or offline documents, avoid the provided CDN HTML template unless you pin, vendor, or self-host Mermaid and understand that browser rendering will execute third-party JavaScript.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:40
Finding

Mutable Remote JavaScript Dependency in Generated HTML

Content
View full analysis
import mermaid from 'https://cdn.jsdelivr.net/npm/mermaid@11/dist/mermaid.esm.min.mjs'; mermaid.initialize({ startOnLoad: true, theme: 'default' }); ``` ### Technical Analysis The HTML template imports and executes Mermaid directly from jsDelivr. The dependency selector `mermaid@11` pins only the major version, so the actual JavaScript returned can change as new version 11 releases are published. The template does not vendor the dependency locally or otherwise verify an immutable artifact. Consequently, the behavior of an already-generated HTML document depends on mutable third-party infrastructure at the time it is opened. If the Mermaid package, package publishing account, npm distribution path, or CDN infrastructure is compromised, malicious JavaScript could be delivered and executed by the browser. This is classified as `T08: Insecure Dependencies` because the risk originates from an externally hosted, mutable third-party dependency and its supply chain. ### Attack Path 1. A user follows the skill instructions and generates an HTML diagram using the provided template. 2. The user opens that HTML document in a browser while network access is available. 3. The browser requests the module identified by `https://cdn.jsdelivr.net/npm/mermaid@11/dist/mermaid.esm.min.mjs`. 4. An attacker who has compromised the relevant package release process, package account, or CDN delivery path causes a malicious version-compatible artifact to be served. 5. The browser executes the returned module in the generated page's origin context without local verification of its contents. This attack path requires compromise or malicious control of an upstream supply-chain component; the audited project itself does not contain a ...[truncated 895 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The HTML example imports Mermaid directly from a public CDN, which causes client-side network access when the file is opened and introduces third-party dependency and privacy/supply-chain exposure. In this skill, users may copy the example into local or internal documentation contexts without realizing it will contact an external host and execute remotely served JavaScript.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.