Rendering architecture diagrams

Skills like Security Architecture Review and Threat Modeling generate a data-flow diagram as part of the report, as Mermaid source. It always shows up as readable text; rendering it as an actual picture in the dashboard is one command away.

Why it's not there by default

The Mermaid renderer is a real, useful piece of JS — and also about 3.5MB, an order of magnitude larger than the rest of secfoo. Rather than bloat every install with it, secfoo ships without it and fetches it once, on demand:

secfoo vendor mermaid

This downloads the bundle into your local store (~/.secfoo/vendor/mermaid.min.js by default) and nothing else — no framework, no build step. Restart secfoo serve if it's already running, and diagrams in any run report render as pictures from then on.

Flags

--urlFetch from a different location instead of the default CDN — useful behind a mirror or an internal proxy.
--forceRe-download even if the bundle is already present.

No outbound network access?

If the machine running secfoo serve can't reach the internet, fetch the file elsewhere and copy it into place yourself — the command tells you exactly where it expects it:

Download failed: <error>
If this machine has no outbound access, fetch the file elsewhere and copy it to:
  ~/.secfoo/vendor/mermaid.min.js

Once the file exists at that path, secfoo serves it locally from then on — the dashboard never calls out to a third party while you read a report, vendored or not.

Why agent-generated diagrams are sanitized

Diagram content comes from the agent CLI reading your target repository, which can itself contain untrusted or adversarial content (a README crafted to inject instructions, say). secfoo renders every diagram with Mermaid's securityLevel: "strict", which disables raw HTML passthrough in labels — the same threat model that keeps the report renderer from executing anything embedded in report markdown.

See secfoo vendor in the CLI reference.