Back to skill

Security audit

Excalidraw Diagram Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill generates Excalidraw diagram files locally; its broad triggers and automatic saving are worth noticing but are disclosed and aligned with that purpose.

Install this if you want Claude/Codex to generate Excalidraw-compatible files. Be aware that it is designed to save files automatically in the current working directory, so use it from an appropriate workspace and watch for filename collisions. If your environment auto-loads skills from generic words like diagram or flowchart, consider narrowing triggers or confirming before file writes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Excalidraw trigger set includes very generic terms such as 'diagram', 'flowchart', and multilingual equivalents that are common in ordinary user requests. In a skill-routing system, overly broad triggers can cause this skill to activate unexpectedly, increasing prompt-scope confusion and making it easier for unrelated requests to be handled by the wrong skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The Mermaid skill uses broad activation terms like 'visualize' and 'flowchart', which are likely to appear in many unrelated requests. This creates an invocation-collision risk where the wrong skill may process content, potentially exposing data to an unintended prompt path or producing unsafe/incorrect outputs due to misclassification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The Canvas skill includes non-specific triggers such as 'mind map' and 'visual diagram', which overlap heavily with normal brainstorming and diagramming requests. In a multi-skill environment, this broad matching can lead to accidental activation and unreliable routing, which is a genuine security and integrity concern for agent behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Excalidraw skill uses broad trigger phrases such as “画图”, “流程图”, and “思维导图”, which are common in normal user requests and overlap with the other skills in this bundle. In an agent skill system that auto-loads skills by phrase matching, this can cause unintended activation, misrouting, or prompt-scope expansion, increasing the chance that the wrong skill influences behavior or output.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Mermaid trigger list includes generic terms like “可视化” and “visualize”, which are highly ambiguous and likely to match many unrelated requests. This makes unintended invocation more likely, especially in an environment with multiple visualization skills, and can lead to incorrect tool selection or unnecessary exposure of the skill’s prompt instructions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The Canvas skill advertises very general trigger phrases such as “思维导图” and “mind map”, which overlap with Excalidraw and other diagramming workflows. In auto-activation contexts, this ambiguity can trigger the wrong skill and create unreliable or manipulable routing behavior, even if the underlying content is not overtly malicious.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains broad terms such as 'diagram' and several common Chinese words for drawing/visualization, which can cause the skill to activate in benign conversations that merely mention those concepts. Over-broad invocation increases the risk that the skill's auto-save and file-generation instructions run unexpectedly, turning a UX issue into a security-relevant side effect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow explicitly says to automatically save to the current working directory, but it does not require prior user consent or warn that local files will be created or potentially overwritten. Automatic filesystem modification from a content-generation skill is dangerous because a casual request can lead to unexpected local side effects without the user's informed approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The implementation section mandates automatic use of the Write tool to save files in the current directory, again without any warning, consent flow, or overwrite safeguards. Because this is an operational instruction rather than a mere suggestion, it materially increases the likelihood of unauthorized or surprising file creation on the host environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs itself to detect environment variables in order to determine the current working directory, which is broader system-context access than is necessary for diagram generation. Even if intended only for convenience, probing environment state increases the chance of exposing host information or enabling unintended file writes in sensitive locations when combined with automatic save behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.