Back to skill

Security audit

Anygen Diagram Generator Free

Security checks for vulnerabilities and agentic risk

Overview

This skill is mainly a diagram generator, but its broad task triggers, command/dependency instructions, and third-party processing of user content warrant Review before installation.

Install only if you are comfortable sending diagram descriptions to AnyGen's external service and giving the agent command execution for the AnyGen workflow. Avoid submitting secrets, credentials, private architecture details, or confidential business data unless your AnyGen account and data-handling terms are acceptable.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The manifest presents the skill as a diagram generator but also advertises broad data analysis, reporting, visualization, and automation uses beyond that scope. This overbroad positioning can cause an agent to invoke the skill for unrelated tasks, increasing the chance of unnecessary external data transmission, unexpected command execution, or misuse of granted read/write/exec capabilities.

Context-Inappropriate Capability

Low
Confidence
90% confidence
Finding
The skill claims file handling, information retrieval, API integration, and general command execution capabilities that are not justified by its stated purpose of diagram generation. Inflated capability claims can prompt an agent to route broader tasks through a skill that has powerful permissions, expanding the attack surface and risking unauthorized file or command operations.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The activation language includes broad phrases such as using the skill for data analysis, report generation, statistical insights, and visualization, which could match many unrelated user requests. Over-triggering is dangerous here because the skill has exec/read/write tools and sends content to an external service, so accidental invocation can expose data or perform actions outside user intent.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill states that text descriptions are converted through the www.anygen.io server-side service, but it does not provide a clear, prominent warning that user content will be transmitted to a third-party external service. This can lead to inadvertent disclosure of sensitive business, architectural, or personal data when users think processing is local or agent-contained.

Static analysis

No suspicious patterns detected.