T09 · Insecure Skill Coding Practices
- Location
generate_flow.py:155- Finding
Path Traversal Enables Unauthorized Local Template File Read
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This looks like a real Draw.io diagram generator, but it has under-scoped local file handling that deserves review before installation.
Review this before installing if agents may run it with untrusted descriptions or template names. It should be safer with an allowlist for template values, proper XML attribute escaping, and explicit confirmation before auto-opening generated files. For trusted personal use, the behavior is understandable, but avoid passing attacker-controlled input until those issues are fixed.
generate_flow.py:155Path Traversal Enables Unauthorized Local Template File Read
generate_flow.py:120Unescaped Description Allows Draw.io XML Attribute Injection
The entire skill description and all usage instructions are written exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. This creates a natural-language locale policy concern because the skill appears to impose a specific language without user opt-in.
The README repeatedly states that the skill directly generates real .drawio files with complete graphical elements and opens them in Draw.io. However, later sections explain the workflow as generating Mermaid code and instruct users to manually import Mermaid into Draw.io, which is a materially different behavior and contradicts the earlier claims.
This Python file contains hard-coded Chinese-language output/content such as the diagram title, while the rest of the tool metadata and CLI are in English. That creates a natural-language locale policy issue because the skill imposes a specific language on users without opt-in or explanation.
The generated diagram title is hard-coded in Chinese, and the file contains many Chinese-only labels throughout the output. Because this code file provides no option for users to select language or locale and no justification that the skill is region-specific, it violates the natural-language locale policy criteria.
The docstring says the tool 'automatically generates a flowchart according to the user description', which implies description-driven generation. In practice, generate_flow only matches a few keywords and then copies a static template file, so the description largely affects only filename/title selection rather than the generated flow logic.
The module docstring and embedded user-facing content present the skill as a Chinese-language flowchart generator and use Chinese labels by default. This creates a locale/language constraint without any visible opt-in or documented choice mechanism, which matches the language-policy violation criteria.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
try:
if sys.platform == "win32":
result = subprocess.run(["where", "draw.io"], capture_output=True, text=True)
else:
result = subprocess.run(["which", "drawio"], capture_output=True, text=True)
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if sys.platform == "win32":
result = subprocess.run(["where", "draw.io"], capture_output=True, text=True)
else:
result = subprocess.run(["which", "drawio"], capture_output=True, text=True)
if result.returncode == 0:
return result.stdout.strip()
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if sys.platform == "win32":
os.startfile(str(drawio_file))
elif sys.platform == "darwin":
subprocess.run(["open", str(drawio_file)])
else:
subprocess.run([drawio_path, str(drawio_file)])
return True
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
elif sys.platform == "darwin":
subprocess.run(["open", str(drawio_file)])
else:
subprocess.run([drawio_path, str(drawio_file)])
return True
except Exception as e:
print(f"[ERROR] Failed to open: {e}")
The manifest description is written as a Chinese-only skill description ('智能流程图生成器 - 根据用户描述自动生成 Mermaid 流程图...') with no indication that users can choose another language or locale. This creates a natural-language locale policy concern because the skill appears to assume a specific language experience without documenting opt-in or alternatives.
This Python file contains natural-language UI/output content in Chinese, beginning with the diagram title at L018 and continuing throughout the generated diagram labels. The policy specifically flags language or locale constraints when a skill forces a specific language without user opt-in, and this file provides no mechanism to select or override the language.
The 'stable version' section instructs users to run stable_generator.py and claims it directly generates draw.io XML, but the later project structure does not include that file and instead lists generate_flow.py plus .mmd Mermaid templates. This is an intent/documentation contradiction rather than a mere omission because the README presents incompatible entrypoints and output models.
The code writes both .mmd and .drawio files into the workspace, which affects user data on disk. Although it prints status messages after writing, there is no prior warning in the docstring or CLI help that running the skill will create files in the current or specified workspace.
The docstring on open_drawio says it will "Open Draw.io with the generated file," and the function also searches for a local Draw.io installation. However, after finding the executable, it ignores that path and calls os.startfile(str(drawio_file)), which opens the file via the system's default association and may launch a different application. This is an intent/documentation mismatch rather than a direct security flaw, but it does contradict the stated behavior.
No suspicious patterns detected.