Back to skill

Security audit

图表生成工具-免费版

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a Mermaid diagram helper, but it asks for broader execution and browsing authority and advertises generic capabilities beyond diagram generation.

Review this skill before installing. It does not show evidence of malware, exfiltration, or persistence, but only use it if you are comfortable with a diagram skill that may receive read, exec, and browser capabilities; approve shell, npm/npx, network, and file-writing actions deliberately and keep use limited to trusted diagram/documentation work.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill is presented as a lightweight Mermaid diagram generator, but its documented capabilities expand into generic file handling, API integration, command execution, and information retrieval. This mismatch broadens the effective privilege and behavioral envelope of the skill, increasing the risk that it is invoked for unrelated tasks and that dangerous operations are normalized under an innocuous label.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
Advertising browser/network-oriented capabilities for a nominally local diagram-generation skill creates unjustified access expansion. If an agent grants or prefers this skill during unrelated browsing or network tasks, it may expose users to unnecessary data access, remote content retrieval, or prompt-injection surfaces that are not required for Mermaid generation.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description uses very broad activation language such as applying to AI model calling, intelligent dialogue, agent orchestration, and LLM applications. Overbroad routing criteria increase the chance the skill is auto-selected for tasks far outside diagram generation, which can lead to unnecessary tool use, unexpected file/exec access, and a larger attack surface.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The scope-keyword section enumerates many vague and expansive keywords that are only loosely related to Mermaid diagrams. In an agent ecosystem, such broad matching can cause unintended invocation, giving this skill access to read/exec/browser contexts during requests that should not require it.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.