Back to skill

Security audit

Draw.io CoderKnock - 智能架构图生成器

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real Draw.io diagram generator, but it has under-scoped local file handling that deserves review before installation.

Review this before installing if agents may run it with untrusted descriptions or template names. It should be safer with an allowlist for template values, proper XML attribute escaping, and explicit confirmation before auto-opening generated files. For trusted personal use, the behavior is understandable, but avoid passing attacker-controlled input until those issues are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
generate_flow.py:155
Finding

Path Traversal Enables Unauthorized Local Template File Read

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
generate_flow.py:120
Finding

Unescaped Description Allows Draw.io XML Attribute Injection

Content
View full analysis
', '>') return f""" ``` The user-controlled description is passed as the title at `generate_flow.py:175`: ```python drawio_xml = self.generate_drawio_xml(mermaid_code, title=description) ``` ### Technical Analysis The application escapes `mermaid_code` before inserting it into XML, but it does not escape the user-controlled `title`. The title is interpolated directly into the double-quoted `name` attribute: ```xml ``` A description containing a double quote can terminate the attribute. XML metacharacters and additional markup can then corrupt or alter the generated Draw.io document. This violates the requirement that untrusted data be encoded according to its XML context. The generated file is subsequently opened automatically in Draw.io when a local installation is detected. Consequently, a crafted description can reach the XML parser without requiring the user to edit the generated file manually. ### Attack Path 1. An attacker controls or influences the flowchart description. 2. The attacker supplies a description containing a quote and crafted XML content, such as a value intended to terminate the `name` attribute and introduce additional attributes or elements. 3. `generate_drawio_xml()` inserts the value without XML attribute encoding. 4. The application writes the malformed or attack ...[truncated 873 chars]
Remediation
View remediation
""" ``` 3. Avoid using only element-text escaping for attribute contexts. Attribute values must also handle quotation marks. 4. Validate the completed document with an XML parser before writing or opening it: ```python ET.fromstring(drawio_xml) ``` 5. Add regression tests using descriptions containing `"`, `'`, `&`, `<`, `>`, and attempted closing tags. 6. Consider requiring explicit user confirmation before automatically opening a document generated from untrusted input. ]]>
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill description and all usage instructions are written exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. This creates a natural-language locale policy concern because the skill appears to impose a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README repeatedly states that the skill directly generates real .drawio files with complete graphical elements and opens them in Draw.io. However, later sections explain the workflow as generating Mermaid code and instruct users to manually import Mermaid into Draw.io, which is a materially different behavior and contradicts the earlier claims.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Python file contains hard-coded Chinese-language output/content such as the diagram title, while the rest of the tool metadata and CLI are in English. That creates a natural-language locale policy issue because the skill imposes a specific language on users without opt-in or explanation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated diagram title is hard-coded in Chinese, and the file contains many Chinese-only labels throughout the output. Because this code file provides no option for users to select language or locale and no justification that the skill is region-specific, it violates the natural-language locale policy criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The docstring says the tool 'automatically generates a flowchart according to the user description', which implies description-driven generation. In practice, generate_flow only matches a few keywords and then copies a static template file, so the description largely affects only filename/title selection rather than the generated flow logic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring and embedded user-facing content present the skill as a Chinese-language flowchart generator and use Chinese labels by default. This creates a locale/language constraint without any visible opt-in or documented choice mechanism, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · generate_flow.py (reported line 110)May include surrounding context.

python
try:
            if sys.platform == "win32":
                result = subprocess.run(["where", "draw.io"], capture_output=True, text=True)
            else:
                result = subprocess.run(["which", "drawio"], capture_output=True, text=True)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · generate_flow.py (reported line 112)May include surrounding context.

python
if sys.platform == "win32":
                result = subprocess.run(["where", "draw.io"], capture_output=True, text=True)
            else:
                result = subprocess.run(["which", "drawio"], capture_output=True, text=True)
            
            if result.returncode == 0:
                return result.stdout.strip()

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · generate_flow.py (reported line 203)May include surrounding context.

python
if sys.platform == "win32":
                os.startfile(str(drawio_file))
            elif sys.platform == "darwin":
                subprocess.run(["open", str(drawio_file)])
            else:
                subprocess.run([drawio_path, str(drawio_file)])
            return True

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · generate_flow.py (reported line 205)May include surrounding context.

python
elif sys.platform == "darwin":
                subprocess.run(["open", str(drawio_file)])
            else:
                subprocess.run([drawio_path, str(drawio_file)])
            return True
        except Exception as e:
            print(f"[ERROR] Failed to open: {e}")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description is written as a Chinese-only skill description ('智能流程图生成器 - 根据用户描述自动生成 Mermaid 流程图...') with no indication that users can choose another language or locale. This creates a natural-language locale policy concern because the skill appears to assume a specific language experience without documenting opt-in or alternatives.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains natural-language UI/output content in Chinese, beginning with the diagram title at L018 and continuing throughout the generated diagram labels. The policy specifically flags language or locale constraints when a skill forces a specific language without user opt-in, and this file provides no mechanism to select or override the language.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The 'stable version' section instructs users to run stable_generator.py and claims it directly generates draw.io XML, but the later project structure does not include that file and instead lists generate_flow.py plus .mmd Mermaid templates. This is an intent/documentation contradiction rather than a mere omission because the README presents incompatible entrypoints and output models.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The code writes both .mmd and .drawio files into the workspace, which affects user data on disk. Although it prints status messages after writing, there is no prior warning in the docstring or CLI help that running the skill will create files in the current or specified workspace.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring on open_drawio says it will "Open Draw.io with the generated file," and the function also searches for a local Draw.io installation. However, after finding the executable, it ignores that path and calls os.startfile(str(drawio_file)), which opens the file via the system's default association and may launch a different application. This is an intent/documentation mismatch rather than a direct security flaw, but it does contradict the stated behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.