Back to skill

Security audit

draw.io Diagrammer Skill

Security checks across malware telemetry and agentic risk

Overview

This is a coherent draw.io diagram-authoring skill with disclosed local file creation and export commands, but users should review output paths and command use.

Install this if you want an agent to create and export draw.io diagrams. Before use, confirm the exact output folder, filenames, and export command, especially when working with untrusted names or custom storage locations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to run local shell commands to create directories and invoke the draw.io desktop/CLI binary for export. Even if intended for legitimate diagram generation, embedded execution steps expand the skill from content generation into host-side command execution, which can be unsafe when file names, paths, or later referenced inputs are influenced by user content or other skill files.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The metadata says to use this skill for any diagram or visualization request, which is broader than a narrowly scoped draw.io authoring workflow. Overbroad activation increases the chance the skill is invoked in contexts where its file-writing, export, and review instructions are unnecessary or inappropriate, expanding exposure to risky behaviors.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes highly generic terms like 'diagram' and broad update/fix language, which can cause the skill to activate for ambiguous requests outside its intended scope. In combination with the skill's imperative workflow and local export steps, unnecessary activation increases operational risk and may steer the agent into performing file or tool actions it otherwise would not take.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.