Back to skill

Security audit

Mermaid Diagrams

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Mermaid diagram documentation skill; the main caution is mutable install and rendering examples, not hidden or malicious behavior.

Before installing, prefer pinned versions or reviewed local copies instead of @latest, mutable GitHub branch URLs, global npm installs, or broad CDN imports. Treat Mermaid click links and HTML CDN examples as outbound network behavior and use trusted destinations only.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:26
Finding

Unpinned Executable Dependencies and Mutable Remote Resources

Content
View full analysis

Vulnerability Details

File Location: README.md:26, README.md:32, SKILL.md:23, SKILL.md:179, and references/advanced-features.md:516
Vulnerability Type: Supply-chain exposure through unpinned packages and remotely hosted executable JavaScript
Risk Level: Medium

Vulnerable Code

README.md:26

bash
npx add https://github.com/wpank/ai/tree/main/skills/writing/mermaid-diagrams

README.md:32

bash
npx clawhub@latest install mermaid-diagrams

SKILL.md:23

bash
npx clawhub@latest install mermaid-diagrams

SKILL.md:179

markdown
- Mermaid CLI — `npm install -g @mermaid-js/mermaid-cli` then `mmdc -i input.mmd -o output.png`

references/advanced-features.md:516

javascript
import mermaid from 'https://cdn.jsdelivr.net/npm/mermaid@10/dist/mermaid.esm.min.mjs';

Technical Analysis

The documented installation commands resolve and execute third-party packages without pinning them to immutable versions or verified artifacts:

  • npx clawhub@latest explicitly selects a mutable release tag.
  • npm install -g @mermaid-js/mermaid-cli does not specify an exact package version and installs the resolved package globally.
  • The GitHub installation URL points to a mutable branch path rather than an immutable commit.
  • npx add ... may resolve and execute a package named add, creating additional ambiguity over which installer is trusted.
  • The CDN import uses the broad @10 major-version selector without an integrity hash. The JavaScript returned for the same documented URL can consequently change after review.

Package-manager installation hooks and npx commands can execute code during dependency resolution and installation. If a registry account, dependency, mutable branch, CDN response, or release process is compromised, the effective code executed by users can differ from the content that was audited.

The CDN example ...[truncated 2052 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every npm package to an exact audited version rather than using @latest or omitting the version:

    bash
    npx clawhub@<exact-version> install mermaid-diagrams
    npm install --save-dev @mermaid-js/mermaid-cli@<exact-version>
    
  2. Replace the mutable GitHub branch URL with an immutable commit reference. Document the expected commit hash and verify downloaded content before installation.

  3. Replace the ambiguous npx add command with an installation method whose package identity, publisher, version, and behavior are explicitly documented and verified.

  4. Prefer a project-local Mermaid CLI dependency over a global installation. Commit the relevant lockfile and use deterministic installation commands such as npm ci.

  5. Review package provenance, signatures, lifecycle scripts, and transitive dependencies before recommending installation. Where supported, enforce registry integrity metadata and trusted publisher policies.

  6. Pin the CDN import to an exact Mermaid release rather than @10. Prefer serving a reviewed local copy. If a compatible loading mechanism is used, enforce Subresource Integrity and an appropriately restrictive Content Security Policy.

  7. Run package installation and diagram rendering under a non-administrative account or isolated container with only the minimum required filesystem and network access.

  8. Periodically review pinned versions for security updates and update them through a controlled process that includes dependency auditing and integrity verification.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (11)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 3)May include surrounding context.

md
# Mermaid Diagrams

Create professional software diagrams using Mermaid's text-based syntax. Mermaid renders diagrams from simple text definitions, making diagrams version-controllable, easy to update, and maintainable alongside code.

## What's Inside

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README says the skill is triggered by requests to 'diagram, visualize, model, map out, or show the flow of a system.' Several of these phrases, especially 'visualize,' 'model,' and 'map out,' are broad natural-language requests that can occur in many contexts unrelated to Mermaid diagrams. The description does not provide limiting context or negative examples to narrow activation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README instructs users to run npx add against a GitHub URL without pinning to an immutable commit or release. This can cause users to fetch different code over time or code from a compromised upstream, creating a supply-chain risk if the referenced repository changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command npx clawhub@latest install mermaid-diagrams explicitly uses @latest, which is mutable and may execute newly published package code without review. If the package is compromised or a malicious version is released, users could run attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 58)May include surrounding context.

From your project root:

bash
mkdir -p .claude/skills
cp -r ~/.ai-skills/skills/writing/mermaid-diagrams .claude/skills/mermaid-diagrams

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 65)May include surrounding context.

Claude Code (global)

bash
mkdir -p ~/.claude/skills
cp -r ~/.ai-skills/skills/writing/mermaid-diagrams ~/.claude/skills/mermaid-diagrams

External Model or Provider Selection

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: mermaid-diagrams
model: fast
version: 1.0.0
description: >
  Create software diagrams using Mermaid syntax. Use when users need to create, visualize,

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use the skill when users need to 'create, visualize, or document software' and lists triggers like 'diagram, visualize, model, map out, or show the flow of a system.' Several of these phrases are broad and could match ordinary planning or explanation requests, without clearly delimiting when the skill should or should not activate. The file also does not provide exclusion conditions or negative examples to narrow scope.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The installation command invokes a remote package via npx clawhub@latest, which is not pinned to a specific immutable version. That creates a supply-chain risk: future upstream changes or a compromised package release could execute unintended code during installation. In the context of a skill distribution document, users may copy-paste the command directly, increasing the chance of exposure.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/flowcharts.md (reported line 370)May include surrounding context.

md
Start([Select deployment strategy]) --> Env{Environment?}
    
    Env -->|Development| DevDecision{Automated tests?}
    DevDecision -->|Pass| DevDeploy[Auto-deploy to dev]
    DevDecision -->|Fail| Block[Block deployment]
    
    Env -->|Staging| StageDecision{All checks pass?}

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file includes Mermaid click events that send users to external websites such as GitHub and mermaid.js.org, but the surrounding documentation does not warn that diagrams can contain outbound links. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that could affect privacy or system integrity, and external navigation is a user-facing behavior worth disclosing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.