Back to skill

Security audit

Excalidraw

Security checks for vulnerabilities and agentic risk

Overview

The skill is a legitimate Excalidraw diagram helper, but its default workflow uploads diagram content to Excalidraw and controls a browser without requiring explicit user consent.

Install only if you are comfortable with agents uploading diagrams to Excalidraw for sharing. Use local .excalidraw file generation for sensitive diagrams, and require explicit approval before upload or browser screenshot steps.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:327
Finding

Unpinned Third-Party Python Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:7, SKILL.md:327, and scripts/upload.py:9-10,29-33
Vulnerability Type: Unpinned dependency installation and supply-chain exposure
Risk Level: Medium

Complete Code Snippets

From SKILL.md:7:

yaml
dependencies: ["cryptography"]

From SKILL.md:327:

text
Requires: `pip install cryptography`

From scripts/upload.py:9-10:

python
Requirements:
    pip install cryptography

From scripts/upload.py:29-33:

python
try:
    from cryptography.hazmat.primitives.ciphers.aead import AESGCM
except ImportError:
    print("Error: 'cryptography' package is required for upload.")
    print("Install it with: pip install cryptography")
    sys.exit(1)

Technical Analysis

The skill requires the cryptography package but does not constrain it to a reviewed version or verify the integrity of the downloaded distribution. It also provides no lockfile or hash-locked requirements file. Running pip install cryptography therefore resolves a package dynamically from the Python package index configured in the user's environment.

This creates supply-chain exposure if the configured package source, dependency resolution path, package release, or network environment is compromised. A malicious source distribution could execute code during package installation, while a malicious wheel or compromised package version could execute attacker-controlled code when imported by scripts/upload.py.

The package name itself is legitimate and no malicious dependency is present in the audited project. The risk arises from the uncontrolled version and artifact selection process.

Attack Path

  1. A user follows the skill documentation and runs pip install cryptography.
  2. Pip queries the package source configured in the user's environment.
  3. An attacker compromises that source, a resolved release, or the user's package-index configuration and serves a malicious artifact under the expecte ...[truncated 896 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a reviewed version rather than resolving the latest available release:
text
cryptography==REVIEWED_VERSION
  1. Provide a hash-locked requirements file containing hashes for every supported distribution, then require hash verification:
bash
python -m pip install --require-hashes -r requirements.txt
  1. Generate and review the lockfile through a controlled dependency-update process. Test and security-review new versions before updating the pin.

  2. Use the official Python package index through authenticated TLS, and document that untrusted mirrors or additional package indexes must not be used.

  3. Install the dependency inside a dedicated virtual environment with minimal privileges rather than into a system-wide or privileged Python environment.

  4. Consider publishing a verified package or environment manifest for each supported platform so users can reproduce the reviewed dependency set.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a diagram-generation helper, but its documented workflow also reads local files, uploads content to a third-party service, generates shareable links, and performs encryption-related processing. That mismatch can mislead users or policy systems into approving the skill for low-risk local content generation when it actually enables data egress and broader side effects.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs use of write_file, local file reads, and network upload behavior, but it declares no explicit tool scope or permission boundaries. In an agent environment, that omission can cause the skill to be invoked with broader-than-expected capabilities, increasing the chance of unintended file access or external transmission without clear policy gating.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill tells the agent to upload diagrams to excalidraw.com but does not require a prominent user warning or consent step before transmitting potentially sensitive diagram contents to a third party. Architecture and flow diagrams often contain internal system names, trust boundaries, or operational details, so silent upload creates a real confidentiality risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 365)May include surrounding context.

bash
# 1. Navigate to the Excalidraw URL
curl -X POST http://localhost:9867/navigate \
  -H "Content-Type: application/json" \
  -d '{"url": "https://excalidraw.com/#json=<FILE_ID>,<KEY>"}'

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script contains explicit functionality to upload local diagram contents to a third-party service over the network, which exceeds a narrowly described 'generate diagrams' capability and creates a data exfiltration path. Although the payload is encrypted client-side and the key stays in the URL fragment, the act of transmitting user-provided files externally still introduces confidentiality, compliance, and unexpected-publishing risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Remote publishing capability is present without being justified by the stated skill purpose, so users or higher-level agents may invoke behavior that sends local content off-host unexpectedly. Even if designed for convenience, hidden or under-disclosed outbound publication can leak sensitive architecture diagrams, internal system names, or embedded secrets contained in the .excalidraw JSON.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The screenshot workflow writes image files locally and interacts with browser-control endpoints on localhost without an explicit warning that it will control a browser session and create artifacts on disk. While localhost access is less severe than internet egress, it still introduces privacy and safety concerns, especially if the browser session contains sensitive state or the endpoint exposes powerful automation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.