Back to skill

Security audit

Diagram Generator

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real diagram generator, but its unauthenticated web server can use the user's Gemini key and manage saved files without sufficient containment.

Review before installing. Run only on a trusted local machine, avoid exposing port 3000 to any network, do not upload secrets or confidential code unless approved for Gemini processing, and prefer a version that binds to 127.0.0.1, removes broad CORS, adds authentication for all /api and /downloads access, pins/bundles browser dependencies, and documents retention/deletion behavior.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
server.js:18
Finding

Unauthenticated Network-Accessible AI and File Management APIs

Content
View full analysis
{ ``` ```js app.post('/api/save', async (req, res) => { ``` ```js app.get('/api/files', async (req, res) => { ``` ```js app.delete('/api/files/:project/:filename', async (req, res) => { ``` ```js app.delete('/api/projects/:project', async (req, res) => { ``` The server is started without restricting it to the loopback interface: ```js app.listen(PORT, () => console.log(`🚀 Server running on http://localhost:${PORT}`)); ``` ### Technical Analysis The application does not authenticate callers or perform user/resource-level authorization on any API. This affects operations that: - Invoke the Gemini API using the server owner's API key. - Save attacker-controlled content to the server. - Enumerate saved projects and filenames. - Retrieve saved files through the public `/downloads` static route. - Delete individual files or entire project directories. Calling `app.listen(PORT)` without a hostname normally binds the service to all available interfaces, not only `localhost`. Consequently, the log message and documentation do not enforce the claimed local-only deployment model. The unrestricted `cors()` middleware permits arbitrary web origins to read responses and invoke supported cross-origin methods. This substantially increases exposure when the service is reachable from a victim's browser, local network, dev ...[truncated 2505 chars]
Remediation
View remediation
{ console.log(`Server running on http://${HOST}:${PORT}`); }); ``` 2. **Add authentication** - Require an authenticated session or bearer token for every `/api/*` route. - Do not treat network location or CORS as an authentication mechanism. - Store authentication secrets outside source control and compare tokens using timing-safe logic where applicable. 3. **Add authorization** - Associate projects with authenticated identities. - Verify ownership before listing, reading, saving, or deleting files. - Avoid exposing the complete downloads directory through unauthenticated static middleware. - Replace the static route with an authorized download controller. 4. **Restrict CORS** ```js app.use(cors({ origin: ['http://127.0.0.1:3000', 'http://localhost:3000'], methods: ['GET', 'POST', 'DELETE'], credentials: true })); ``` Omit CORS entirely if the frontend is always served from the same origin. 5. **Add abuse controls** - Rate-limit generation, save, list, download, and delete endpoints. - Apply stricter per-route body limits. - Limit the number and decoded size of files per request. - Reject malformed or oversized base64 content before processing it. - Introduce Gemini request quotas per authenticated user. 6. **Protect destructive operations** - Require authorization and CSRF protection when cookie-based sessions are used. - Consider soft deletion, audit logging, or recovery retention for projects. - Return appropriate errors without disclosing unnecessary implementation details. 7. **Harden path containment checks** - Use `path.resolve()` and compare against a downloads-root path ending with the platform separator. - Continue applying strict project and filename validation. - Prevent symbol ...[truncated 84 chars]

T03 · Remote Payload Retrieval and Execution

Warning
Location
public/app.js:13
Finding

Runtime Retrieval and Execution of Unpinned Third-Party JavaScript

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (29)

Known Vulnerable Dependency: protobufjs==7.5.4 — 12 advisory(ies): CVE-2026-44294 (protobuf.js: Denial of service from crafted field names in generated code); CVE-2026-44293 (protobuf.js: Code injection through bytes field defaults in generated toObject c); CVE-2026-44289 (protobuf.js: Denial of service through unbounded protobuf recursion) +9 more

Critical
Category
Supply Chain
Confidence
90% confidence
Finding

protobufjs 7.5.4 carries multiple serious advisories including denial-of-service and potential code-generation/injection issues. Although the lockfile does not prove active exploitation, this package is a runtime transitive dependency of @google/genai, so the skill ships with a dependency version that may become reachable if it handles model responses, schemas, or protobuf-derived data from external services.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
**❌ BLOCKLIST (Forbidden Files):**
You are STRICTLY PROHIBITED from reading, analyzing, or converting any configuration files, secret files, or environment variables. This includes, but is not limited to:
- `.env`, `.env.local`, or any environment files.
- `secrets.json`, `credentials.yml`, or AWS/GCP config folders.
- `id_rsa`, `.pem`, or any SSH/encryption keys.
- Hidden system directories (e.g., `.git/`, `.ssh/`).

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
**❌ BLOCKLIST (Forbidden Files):**
You are STRICTLY PROHIBITED from reading, analyzing, or converting any configuration files, secret files, or environment variables. This includes, but is not limited to:
- `.env`, `.env.local`, or any environment files.
- `secrets.json`, `credentials.yml`, or AWS/GCP config folders.
- `id_rsa`, `.pem`, or any SSH/encryption keys.
- Hidden system directories (e.g., `.git/`, `.ssh/`).

Known Vulnerable Dependency: brace-expansion==5.0.5 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-45149 (brace-expansion: Large numeric range defeats documented `max` DoS protection); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Possible Typosquatting: 'gaxios' resembles popular package 'axios'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.20.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
86% confidence
Finding

ws 8.20.0 is a runtime transitive dependency of @google/genai and the cited advisories include memory disclosure and memory exhaustion. Because this skill supports multimodal AI interactions and may rely on streaming or websocket-capable libraries, a vulnerable ws version in the runtime dependency tree increases the risk of remotely triggerable denial of service or data exposure if those code paths are used.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The application exposes destructive delete operations for both individual files and entire projects via simple UI actions calling backend DELETE endpoints, but the skill description only mentions generating and editing diagrams. Hidden or under-disclosed destructive capabilities increase the risk of accidental or socially engineered data loss, especially if an agent can invoke these actions without users appreciating that persistent server-side assets may be removed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly promotes sending source code files, images, and PDFs to an external AI service, but does not warn users that potentially sensitive data will leave their environment and be processed by a third party. In a developer tool that encourages reverse-engineering code and architecture artifacts, this omission can lead to accidental disclosure of proprietary code, secrets embedded in files, or internal design information.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The skill declares capabilities that require environment access and network communication but does not explicitly scope or constrain those powers with a permissions or allowed-tools declaration. In this context, the skill reads local workspace files and sends their contents to a local service backed by Gemini, so missing tool scoping increases the chance of unintended file access or data egress beyond what the user expects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to collect local file contents and images, then POST them to a localhost service that is explicitly backed by the Gemini API, but it does not clearly warn the user that their data may be transmitted to an external model provider. This creates a meaningful privacy and data-handling risk because users may provide source code, documentation, or images under the false assumption that processing remains purely local.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Attached context files, including text documents, PDFs, and images, are automatically packaged and sent to the backend when generating a diagram, but the code provides no explicit transmission warning, consent prompt, or sensitivity notice. Users may attach source code, internal documents, or architecture diagrams assuming local processing, leading to unintended disclosure of confidential data to the server and potentially onward to an AI provider.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a diagram generator/editor with multimodal context support, but this code also saves generated artifacts to server storage and enumerates saved projects/files. Those persistent file-management operations are broader than the stated generation/editing behavior and are not presented in the manifest description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The UI exposes file attachment and local code loading features for many sensitive file types, but provides no warning that uploaded/local content may be processed by the application or sent to backend/AI services. In a multimodal diagram-generation skill that explicitly reads source code and documentation, this increases the risk of users unintentionally disclosing proprietary code, credentials, internal architecture, or personal data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The server concatenates user-supplied document text verbatim into the model prompt, so any secrets, credentials, or confidential architecture details in uploaded files are directly exposed to the model and can be reproduced in the generated diagram output. Because this skill is specifically designed to ingest code and documentation, the context increases the chance that highly sensitive content will be included.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

User prompts and uploaded file contents, including binary documents and extracted text, are transmitted to an external Google GenAI service. In a diagram-generation skill that accepts source code, architecture documents, images, and PDFs, this can expose proprietary or sensitive data to a third party without any evidence in this file of consent, minimization, or policy enforcement.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a skill focused on generating and iteratively editing Mermaid.js and Draw.io diagrams from multimodal context. However, the code also implements a local project/file management API that saves files, lists stored projects, deletes individual files, and deletes entire projects, which is a broader persistent storage capability than the stated diagram-generation purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Deleting arbitrary saved files and whole project directories is a destructive capability that is not mentioned in the manifest description, which only discusses generating and iteratively editing diagrams with multimodal context. While saving outputs may support editing workflows, exposing deletion of stored artifacts and entire projects is a broader capability that should be explicitly justified or declared.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README advertises saving files directly to the server without explaining that generated diagrams may persist server-side, potentially be overwritten, or become accessible to other users depending on deployment configuration. In a web application handling user-supplied diagrams and derived content from source materials, lack of disclosure increases the risk of unintended retention and data loss.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
You may ONLY read and process standard source code files (e.g., `.js`, `.ts`, `.py`, `.java`, `.cpp`, `.html`, `.css`), documentation (e.g., `.md`, `.txt`), or safe images (`.png`, `.jpg`). 

**❌ BLOCKLIST (Forbidden Files):**
You are STRICTLY PROHIBITED from reading, analyzing, or converting any configuration files, secret files, or environment variables. This includes, but is not limited to:
- `.env`, `.env.local`, or any environment files.
- `secrets.json`, `credentials.yml`, or AWS/GCP config folders.
- `id_rsa`, `.pem`, or any SSH/encryption keys.

Known Vulnerable Dependency: @protobufjs/utf8==1.1.0 — 1 advisory(ies): CVE-2026-44288 (protobufjs has overlong UTF-8 decoding)

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: body-parser==1.20.4 — 1 advisory(ies): CVE-2026-12590 (body-parser vulnerable to denial of service when invalid limit value silently di)

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: qs==6.14.2 — 3 advisory(ies): CVE-2026-82417 (qs: Denial of Service via Attacker Controlled isBuffer); CVE-2026-8723 (qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/u); CVE-2026-82562 (qs array-limit bypass via bracket-key comma parsing)

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 14)May include surrounding context.

json
"test:skill": "concurrently \"npm run start\" \"openclaw\" --names \"SERVER,AGENT\" --prefix-colors \"blue,magenta\""
  },
  "dependencies": {
    "@google/genai": "^1.45.0",
    "cors": "^2.8.5",
    "dotenv": "^17.3.1",
    "express": "^4.19.2"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 15)May include surrounding context.

json
},
  "dependencies": {
    "@google/genai": "^1.45.0",
    "cors": "^2.8.5",
    "dotenv": "^17.3.1",
    "express": "^4.19.2"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 16)May include surrounding context.

json
"dependencies": {
    "@google/genai": "^1.45.0",
    "cors": "^2.8.5",
    "dotenv": "^17.3.1",
    "express": "^4.19.2"
  },
  "devDependencies": {

Static analysis

No suspicious patterns detected.