Back to skill

Security audit

Excalidraw MCP

Security checks across malware telemetry and agentic risk

Overview

This skill is a narrowly scoped Excalidraw MCP connector that discloses its use of the OOMOL CLI, credentials, and write actions.

Before installing, make sure you are comfortable using OOMOL as the intermediary for Excalidraw MCP actions. Review any create_view payload before approving it, since that action changes Excalidraw MCP state, and only run the first-time CLI install/login steps if you trust the OOMOL CLI source.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger text is extremely broad: it directs the agent to use this skill for ANY Excalidraw MCP request and for any task involving Excalidraw MCP instead of calling the API directly. Overbroad routing can cause unintended invocation in loosely related contexts, increasing the chance of unnecessary external calls, accidental writes, or bypass of more specific skills or safer handling paths.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.