Back to skill

Security audit

Drawio Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent draw.io diagram skill with disclosed local tooling and network logo behavior, though users should note two generated-HTML escaping bugs.

Install only if you are comfortable with a skill that runs local draw.io/Python tooling over files you choose. Avoid using attacker-controlled filenames or repository directory names with the HTML animation helpers until the title escaping bug is fixed, and use embedded or local assets if CDN logo lookups are not acceptable.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/buildup.py:164
Finding

Stored HTML Injection Through an Unescaped Diagram Filename

Content
View full analysis
{title} ...

{title}

``` The untrusted title originates from the input filename and is written to the generated HTML: ```python title = os.path.splitext(os.path.basename(args.file))[0] + " — build-up" with open(out, "w", encoding="utf-8") as f: f.write(build_html(frames, title)) ``` ### Technical Analysis The basename of the user-selected `.drawio` file is treated as trusted HTML. It is interpolated directly into both the `` element and, more importantly, the `<h1>` element without HTML escaping. On platforms that allow angle brackets and other HTML-significant characters in filenames, such as common Unix filesystems, a filename can contain an event-bearing element such as: ```text <img src=x onerror=alert(document.domain)>.drawio ``` When `buildup.py` processes this file, the resulting heading contains executable HTML: ```html <header><h1><img src=x onerror=alert(document.domain)> — build-up</h1></header> ``` The image load fails and invokes the attacker-controlled event handler when the generated HTML is opened. Escaping the JSON payload does not mitigate this issue because the vulnerable value is independently interpolated into HTML markup. ### Attack Path 1. An attacker creates or ...[truncated 1183 chars]
Remediation
View remediation
{safe_title} ...

{safe_title}

``` 4. Keep the original unescaped value only for non-HTML processing where necessary. 5. Add regression tests with filenames containing HTML metacharacters and event-bearing markup, including: ```text .drawio ``` 6. Assert that the generated output contains escaped text such as `<img` and does not contain an executable `` element. 7. Consider a shared HTML-template helper that performs context-appropriate escaping by default, reducing the chance of similar errors in future generators. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/timelapse.py:117
Finding

Stored HTML Injection Through an Unescaped Repository Directory Name

Content
View full analysis
{title} ...

{title}

``` The title is derived from the analyzed directory basename: ```python title = f"Architecture evolution — {os.path.basename(os.path.abspath(args.path))}" open(args.output, "w", encoding="utf-8").write(build_html(frames, title)) ``` ### Technical Analysis The basename of the directory supplied through `args.path` is inserted directly into HTML markup without context-appropriate escaping. Although frame metadata is serialized through `json.dumps()` and the ` ``` The generated heading then becomes: ```html

Architecture evolution —

``` Opening the generated architecture-history player causes the browser to parse the injected element and execute its event handler. ### Attack Path 1. An attacker prepares a Git repository or analyzed subdirectory with an HTML-bearing basename. 2. The victim clones, extracts, ...[truncated 1057 chars]
Remediation
View remediation
{safe_title} ...

{safe_title}

``` 4. Preserve the existing JSON serialization and `
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (92)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill references a helper that fetches AI brand logos via CDN, introducing external network access into what is presented primarily as a local draw.io workflow. Undeclared or weakly declared outbound fetching can leak prompt-derived identifiers, violate offline expectations, and create supply-chain/trust exposure through remote assets.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/autolayout.py:353

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/c4.py:92

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/tfimports.py:119

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/tfstate.py:33