Back to skill

Security audit

diagram-generator

Security checks for vulnerabilities and agentic risk

Overview

This diagram skill is mostly coherent, but it needs review because its setup recommends running an unpinned npm MCP server and it can write diagram files to custom paths.

Install only if you are comfortable running the external MCP server. Prefer pinning and reviewing the `mcp-diagram-generator` npm package version, running it in a restricted environment, and checking any requested output path before generation. Expect it to create diagram output directories and a `.diagram-config.json` file.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:30
Finding

Unpinned Third-Party Package Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 30-42
Vulnerability Type: Unpinned runtime dependency execution
Risk Level: Medium

Vulnerable Code

json
If the tools are missing, configure the MCP server.

Recommended remote configuration:

{
  "mcpServers": {
    "mcp-diagram-generator": {
      "command": "npx",
      "args": ["-y", "mcp-diagram-generator"]
    }
  }
}

Technical Analysis

The recommended configuration invokes npx with the -y option and an unversioned package name. This causes the package manager to resolve, download, and execute a package from the configured npm registry without interactive confirmation.

No exact version, lockfile, integrity hash, or reviewed package source is included in the project. Consequently, the code executed at runtime may differ from the code that existed when this Skill was audited. The local package.json only contains package metadata and does not constrain the MCP server dependency.

This creates a supply-chain risk: compromise of the package publisher account, npm registry resolution, a transitive dependency, or a future package release could introduce arbitrary executable code.

Attack Path

  1. An attacker compromises the mcp-diagram-generator package, its publisher account, or a dependency resolved by the package.
  2. The attacker publishes a malicious version that contains an installation hook or malicious MCP server implementation.
  3. An agent loads this Skill and determines that the required MCP tools are unavailable.
  4. Following SKILL.md, the environment configures and runs npx -y mcp-diagram-generator.
  5. npx retrieves the currently resolved package version and executes it without asking for confirmation.
  6. The malicious code runs with the operating-system privileges and accessible environment of the agent process.

Impact Assessment

Successful exploitation could permit arbitrary code ...[truncated 499 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the MCP server to a specifically reviewed version, for example:
    json
    {
      "command": "npx",
      "args": ["-y", "mcp-diagram-generator@1.2.1"]
    }
    
  2. Prefer a locally installed dependency recorded in package.json and a committed lockfile containing registry integrity metadata.
  3. Review the pinned package, its lifecycle scripts, and its transitive dependencies before deployment.
  4. Avoid automatic installation at Skill runtime. Require explicit user or administrator approval before downloading executable packages.
  5. Where supported, install dependencies with lifecycle scripts disabled and only enable scripts that have been reviewed.
  6. Execute the MCP server in a restricted environment with minimal filesystem access, sanitized environment variables, and limited network permissions.
  7. Use trusted registry configuration and dependency-monitoring controls to detect publisher compromise, unexpected version changes, and integrity failures.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The phrase "Always use this skill when the user asks to draw, generate, revise, or export any diagram" is very broad and lacks limiting conditions or exclusions. While diagram-related, it does not provide negative examples or scope boundaries, which could cause the skill to be invoked in borderline cases where a request only loosely relates to diagrams.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to generate diagrams and write files to default or user-specified paths, but it does not require an explicit warning or confirmation before filesystem writes occur. In an agent setting, this can lead to unexpected file creation or overwriting in the workspace, especially when custom filenames or output paths are accepted from user input.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Lines L48-L57 define behavior based on Chinese terms such as 开始, 审批, and 退回, which creates language-dependent behavior in a general playbook. Because the file does not state that the skill is intended specifically for Chinese-language workflows or provide an opt-in choice, this can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.