PlantUML

Security checks across malware telemetry and agentic risk

Overview

This PlantUML skill is a small markdown-only helper that generates diagram files in a disclosed workspace folder.

Install if you want an agent to create PlantUML source files for you. Expect it to write generated .puml files under plantuml-src in your workspace, and review filenames or existing files if overwrite behavior matters to you.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to write generated `.puml` files into the user's workspace without requiring prior user confirmation or presenting a clear warning that files will be created or modified. In agentic environments, silent workspace writes can surprise users, overwrite existing content, or be chained with other behaviors to stage artifacts the user did not knowingly authorize.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal