Back to skill

Security audit

Mermaid Diagram Tool Free

Security checks across malware telemetry and agentic risk

Overview

This Mermaid diagram skill is not malicious, but it asks for command execution and includes broad, under-scoped operations beyond simple diagram code generation.

Review this skill before installing. It appears intended for Mermaid diagram generation and I found no evidence of theft, destruction, or hidden persistence, but it should ideally remove or tightly scope exec access and clarify that create, modify, delete, save, import, and export operations apply only to user-requested Mermaid diagram output or preview files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill’s declared purpose is simple Mermaid code generation, but the documentation introduces generic create/query/modify/delete, import/export/save/convert, and reset operations without defining strict scope boundaries. In an agent environment, this kind of capability inflation can cause the agent to interpret unrelated user requests as permission to perform broader state-changing actions than intended.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
A basic text-to-Mermaid skill should not require broad exec capability or network-diagnostic shell commands such as ping in routine troubleshooting guidance. Granting exec to a loosely scoped skill increases the chance of command execution abuse, environment probing, or unintended local actions if an agent follows the documentation too literally.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The auto-activation condition is very broad, triggering on common requests about flows, sequence diagrams, mind maps, or general visualization needs. Overly permissive triggers can cause accidental invocation on ordinary conversations, increasing the chance that the skill overrides user intent, leaks context into tool use, or combines with other risky permissions like exec.

Vague Triggers

Low
Confidence
80% confidence
Finding
The example trigger phrase uses ordinary natural language that many non-skill interactions could also contain, which reinforces ambiguous activation boundaries. While not severe alone, it contributes to accidental skill firing and becomes more concerning because the skill advertises broader-than-needed operations and exec support elsewhere in the file.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.