Back to skill

Security audit

ProcessOn Diagram Generator

Security checks for vulnerabilities and agentic risk

Overview

This ProcessOn diagram skill has a coherent diagram-generation purpose, but it asks for broad automatic routing, remote authentication, mutable updates, token storage, and automatic package installation with insufficient containment.

Install only if you are comfortable sending diagram prompts and related context to ProcessOn, storing a local bearer token, and allowing npm-based dependency setup. Prefer a version pinned to a reviewed commit, avoid forced global updates, and do not use this with secrets, proprietary architecture details, or regulated data unless your organization approves ProcessOn for that use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:3
Finding

Mandatory Skill Routing Overrides Agent Tool Selection

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:19
Finding

Mutable Remote Skill Update Can Replace Reviewed Code and Instructions

Content
View full analysis
{let data='';res.on('data',c=>data+=c);res.on('end',()=>console.log(JSON.parse(data).version));}); req.on('timeout',()=>req.destroy(new Error('timeout'))); req.on('error',()=>process.exit(1));" ``` ```bash npx skills add https://github.com/processonai/processon-skills.git --skill processon-diagram-generator --force -g -y ``` ### Technical Analysis The Skill requires a remote version check against the mutable `main` branch on every use. When a newer version is advertised, the instructions require interruption of the user's task and promote installation from the same mutable repository. The installation command is not pinned to a reviewed commit hash, immutable release archive, or cryptographically verified artifact. Consequently, the code and instructions installed by the command can differ from the version that was audited. The flags `--force`, `-g`, and `-y` further increase risk by replacing existing content, installing globally, and suppressing interactive confirmation. The version-check instructions also direct the Agent to conceal network or parsing failures by treating them as “no update,” reducing transparency around a security-sensitive update mechanism. ### Attack Path 1. An attacker compromises the upstream repository, maintainer account, DNS path, or release workflow. 2. The attacker modifies the mutable `main` branch and increases the advertised version. 3. The mandatory version check detects the attacker-controlled version. 4. The Agent interrupts the user's task and re ...[truncated 797 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
setup.mjs:75
Finding

Automatic npm Execution and Global Dependency Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
setup.mjs:23
Finding

Environment-Controlled MCP Endpoint Can Receive the Stored Bearer Token

Content
View full analysis
{ const child = spawn(process.execPath, ["-e", nodeSpawnHttpScript], { stdio: ["pipe", "pipe", "pipe"], windowsHide: true, }); child.stdin.end(JSON.stringify({ mcpUrl: config.mcpUrl, authorization, toolName, argsPayload, })); }); } ``` ### Technical Analysis The fallback MCP client reads a persisted ProcessOn bearer token and sends it in the `Authorization` header to `config.mcpUrl`. The destination is controlled by the `PO_MCP_URL` environment variable. No hostname allowlist, origin binding, HTTPS requirement, or user confirmation protects this credential-bearing request. The embedded HTTP client explicitly supports both `http:` and `https:` URLs. An attacker who can influence the process environment can therefore redirect the bearer token and diagram prompt to an attacker-controlled server. This does not establish intentional exfiltration under the default configuration, which targets ProcessOn over HTTPS ...[truncated 1140 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
setup.mjs:487
Finding

Public Hard-Coded Shared Secret and Unauthenticated Authorization-Code Construction

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (36)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill declares a mandatory trigger for broad and ambiguous phrases like 'draw', 'generate chart', and 'visualize', and explicitly tells the agent not to skip the skill. This can hijack a wide range of user requests, override safer/native handling paths, and unnecessarily route benign prompts into a workflow that performs network access, auth, and command execution.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation rules include a catch-all requirement for any request containing generic drawing or visualization language, making the skill eligible far beyond its least-privilege purpose. In context, this is especially risky because the skill couples broad auto-invocation with remote auth, update logic, and shell-based orchestration, amplifying the blast radius of misrouting.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 177)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 178)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 180)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 181)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
node ./setup.mjs processon_check_and_start_auth

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

checkMcporter() will run npm install -g mcporter@... on the host when the tool is absent. Global package installation modifies the host environment and executes install scripts with the user's privileges, which is an unjustified and high-risk capability for a skill whose advertised function is only diagram generation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README instructs users to install and run a remote skill via npx skills add from a GitHub repository without pinning to a specific immutable version, tag, or commit. This creates a supply-chain risk: repository changes or compromised upstream dependencies could cause users to fetch and trust different code than was originally reviewed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The update command uses npx skills add ... --force -g -y without pinning a version, which increases supply-chain exposure by forcing replacement with whatever content is currently served from the remote repository. If the repo or its delivery path is compromised, users may silently install altered skill behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states that the skill uses browser-based authorization and returns generation outputs, but it does not clearly warn that users are redirected to an external ProcessOn service and may transmit prompts, diagrams, or code context to that third party. This omission can lead users to disclose sensitive business logic or source code without informed consent, especially because the skill explicitly supports natural language and code context.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes shell commands, accesses environment-capable runtime components, performs network requests, and manages OAuth/token state, yet it declares no explicit tool scope or permission boundary. This creates a mismatch between what the skill appears to require and what it actually does, increasing the chance of over-privileged execution and reducing reviewability.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
setup.mjs:57

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
setup.mjs:120