Back to skill

Security audit

Diagram生成器

Security checks for vulnerabilities and agentic risk

Overview

The skill is for diagram generation, but its setup tells agents to run an unpinned external package with execution rights, which needs review before installation.

Install only if you are comfortable running the connector in a restricted environment. Prefer pinning and reviewing the connector package first, limit filesystem access to the intended input/output directories, avoid exposing unrelated environment variables or API keys, and confirm before overwriting existing diagram files or using callback URLs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:102
Finding

Unpinned Third-Party Package Is Downloaded and Executed Automatically

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 102-106; repeated at line 325
Vulnerability Type: Unpinned dependency execution and software supply-chain exposure
Risk Level: Medium

Vulnerable Code

json
{
  "protocolServers": {
    "connector-diagram-generator": {
      "command": "npx",
      "args": ["-y", "connector-diagram-generator"]
    }
  }
}

The same unsafe installation pattern is repeated in the setup guidance:

text
Set `command` to `npx` and `args` to `["-y", "connector-diagram-generator"]`.

Technical Analysis

The Skill directs users to invoke connector-diagram-generator through npx -y without specifying an exact package version, integrity hash, lockfile, trusted registry, or verified publisher identity.

When the package is not already available locally, npx can retrieve it from the configured npm registry and execute its entry point. The -y option suppresses the normal installation confirmation. Consequently, the executable code run by the Agent is not immutable: it may differ from the code that existed when this Skill was reviewed.

This creates a supply-chain boundary in which compromise of the package publisher, npm account, registry resolution, or a transitive dependency could result in arbitrary code execution. The audit could not verify the connector because the project contains only SKILL.md; it does not include the connector source, a package manifest, a lockfile, or integrity metadata.

Attack Path

  1. An attacker compromises the connector-diagram-generator package, its publisher account, or one of its resolved dependencies.
  2. The attacker publishes a malicious version under the package name used by the Skill.
  3. A user follows the documented setup instructions.
  4. npx -y connector-diagram-generator resolves and downloads the mutable package version without requesting interactive confirmation.
  5. npx executes the package entry point with the privileges and environment o ...[truncated 1237 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the connector to an exact, reviewed version rather than resolving the latest mutable release:

    json
    {
      "protocolServers": {
        "connector-diagram-generator": {
          "command": "npx",
          "args": [
            "--yes",
            "--package=connector-diagram-generator@1.2.3",
            "connector-diagram-generator"
          ]
        }
      }
    }
    
  2. Record and verify package integrity through a committed lockfile and registry-provided integrity hashes. Prefer a controlled installation step such as npm ci over runtime package resolution.

  3. Verify and document the expected package publisher, package registry, source repository, and reviewed release checksum. Reject packages resolved from unexpected registries.

  4. Avoid unattended -y installation where practical. Separate dependency installation and approval from connector execution so users can inspect the resolved version before running it.

  5. Prefer vendoring or bundling a reviewed connector artifact when operationally feasible. Sign releases and verify signatures or checksums before execution.

  6. Run the connector in a restricted environment:

    • Use a dedicated unprivileged operating-system account.
    • Limit filesystem access to required input and output directories.
    • Expose only essential environment variables.
    • Do not pass unrelated credentials or API keys.
    • Restrict outbound network access to explicitly required destinations.
    • Apply process, resource, and execution limits.
  7. Add an upgrade-review process so version changes require source review, dependency scanning, integrity regeneration, and regression testing before deployment.

  8. Update both occurrences of the setup instruction, including the repeated guidance at line 325, to prevent users from falling back to the unsafe command.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation language is very broad and overlaps with generic productivity, automation, and workflow tasks. In agent routing contexts, this can cause the skill to be invoked outside its narrow purpose, increasing the chance that its exec, write, and connector-related instructions are applied in unsafe or unintended situations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill accepts a callback_url for asynchronous completion without clearly warning that this may trigger outbound network requests. This can enable unintended data exfiltration, SSRF-like behavior, or disclosure of task metadata to external endpoints if users or downstream components supply untrusted URLs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill requests API key environment-variable setup even though the documented capability is local diagram generation/editing. This expands the trust boundary, may prompt unnecessary secret handling, and increases the risk of credential exposure through logs, shell history, or misuse by downstream tools.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to launch an external package via npx -y connector-diagram-generator, which can fetch and execute remote code at runtime. That behavior is broader than diagram generation itself and creates a supply-chain and arbitrary code-execution risk, especially in agent environments where users may not realize package execution will occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill describes creating files and overwriting outputs without a clear user-facing warning or confirmation step. In an agent environment with write access, this can lead to unintended modification or destruction of local files, especially when editing existing diagrams or using caller-provided output paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The visible display name, summaries, and most operational instructions are in Chinese, while some technical fragments remain in English. This creates an implicit language preference without stating that users may choose another language, which can violate language/locale policy when no opt-in is offered.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Line L035 declares PPT slide work is out of scope, but later sections prescribe PPT-oriented behavior such as choosing layouts for PPT readability and PPT presentation use. That is an active contradiction between scope documentation and later operational instructions, not merely an omitted detail.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This line explicitly prioritizes layout choices for Word and PPT scenarios, which conflicts with the earlier statement that PPT slides are outside the skill's scope. The contradiction is reinforced as operational guidance, suggesting intended support for PPT-adjacent use despite the exclusion.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.