GeoGebra Diagram Generator

AdvisoryAudited by Static analysis on May 13, 2026.

Overview

No suspicious patterns detected.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The agent may open GeoGebra and paste the generated construction into the page for verification.

Why it was flagged

The skill may drive a browser, write to the browser clipboard, and submit generated GeoGebra commands to an external website. This is directly aligned with the diagram-generation purpose, but users should be aware of the browser action.

Skill content
Open `https://www.geogebra.org/geometry`... Write the whole `Execute({...})` command to the browser clipboard, paste it, then press Enter.
Recommendation

Review the generated GeoGebra command before browser execution if the geometry problem contains sensitive or private content.

What this means

A generated construction command could be executed directly in the open GeoGebra page instead of pasted manually.

Why it was flagged

The skill documents a fallback that runs a generated GeoGebra command through a page JavaScript API. It is disclosed and purpose-aligned, but it is still a dynamic execution path inside the browser page.

Skill content
If the browser exposes a JavaScript evaluation surface and clipboard paste is not available, injecting through GeoGebra's applet API can still work: `ggbApplet.evalCommand(...)`
Recommendation

Prefer the paste workflow when possible, and only use the JavaScript fallback on the intended GeoGebra page after checking the command.