Back to skill

Security audit

draw.io Diagrammer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent draw.io diagram helper that creates and reviews local diagram files without hidden credential use, persistence, or unrelated actions.

Install if you want an agent to create and visually inspect draw.io diagrams. Be aware it may invoke for broad visualization requests, and it expects local file creation plus a draw.io CLI export workflow; review cloud/share-link destinations before asking the agent to move or share finished files.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The top-level skill description says it should be used when the user requests 'any diagram or visualization,' which is broader than the concrete, controlled use cases listed later. Overbroad activation increases the chance the agent invokes this skill for loosely related requests, causing unnecessary file operations, diagram-generation workflows, or command usage in contexts where they are not appropriate.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes generic phrases such as 'diagram' and 'visualize this process,' which can collide with ordinary requests that do not actually require this skill. In an agentic environment, such broad triggers can lead to inappropriate skill activation, expanding the skill’s operational reach beyond intended scenarios and increasing exposure to unnecessary tool or filesystem actions.

Static analysis

No suspicious patterns detected.