diagram-generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent diagram-generation helper, with expected file-writing behavior that users should keep scoped to their project.

Install only if you are comfortable adding the companion MCP server. Prefer the default diagram folders and timestamped filenames, review any custom output_path or filename, and explicitly confirm before overwriting an existing diagram.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation explicitly instructs users to overwrite existing diagram files or regenerate them in place, but it does not warn about data loss, accidental destruction of prior versions, or the need for confirmation/backup behavior. In a file-generating skill, this can lead to unintended loss of user-authored diagrams, especially when an agent acts automatically on a vague modification request.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The documentation allows fully custom relative or absolute output paths with no warning or constraint, which enables writes outside the expected workspace or diagram directory. In an agent skill that generates files on behalf of a user, this increases the risk of arbitrary file overwrite, clobbering sensitive files, or writing into unintended locations if user input is malicious or ambiguous.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal