Back to skill

Security audit

diagram-to-code

Security checks for vulnerabilities and agentic risk

Overview

The skill is a simple diagram-to-code instruction package with some scaffolded documentation gaps, but no artifact-backed hidden execution, persistence, exfiltration, or destructive behavior.

This appears safe to install as a text-generation skill, but treat the README as unfinished scaffolding: do not provide an API key or run any write-mode workflow unless the publisher documents what service is used and exactly what files will be changed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose says the skill should be used when a user provides an architecture diagram and wants infrastructure or component code generated. However, the supplied code chunk contains only automated tests for skill packaging/documentation compliance. Its primary function is QA/linting of a skill repository, not diagram interpretation or code generation. The file access patterns are also inconsistent with the declaration: it reads SKILL.md, README.md, tests/, scripts/, and scans local files for secrets rather than consuming user diagrams or emitting IaC/component code. This is not a supporting implementation detail; it is a materially different primary purpose.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
- Do not make up facts or claim actions were taken that were not
- Do not hardcode API keys — use `os.getenv("API_KEY")` instead
- Do not store sensitive user data beyond the current session
- Do not exceed token budget without warning the user first
- Do not activate for off-topic requests — return a brief decline message

### Do

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README leaves the trigger condition as a placeholder ('When triggered: [trigger condition]'), so the activation scope is undefined. In an agent skill, ambiguous invocation criteria can cause the skill to run in unintended contexts, increasing the chance of unsafe or inappropriate code-generation behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README advertises a '--mode write' operation but does not warn that it may create or modify files or outputs. This can mislead users or orchestrators about side effects, raising the risk of unintended file changes, overwrites, or unsafe automation when the skill is invoked in write mode.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This markdown file says '触发条件: [trigger condition]。' without defining any concrete trigger phrase, scope, or exclusion conditions. That makes invocation criteria ambiguous and can lead to unintended or inconsistent activation because users are not told when the skill should or should not be used.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest says this skill is for converting an architecture diagram into infrastructure-as-code or component code. However, the usage section describes generic "read" and "write" modes with a JSON input file, which does not match the stated diagram-to-code behavior and suggests a broader or different operation than the manifest claims.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
- Do not make up facts or claim actions were taken that were not
- Do not hardcode API keys — use `os.getenv("API_KEY")` instead
- Do not store sensitive user data beyond the current session
- Do not exceed token budget without warning the user first
- Do not activate for off-topic requests — return a brief decline message

### Do

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The test test_readme_zh_exists requires a Chinese-language README file (README_zh.md) to exist, which is a natural-language policy constraint embedded in code. This hard requirement can force a specific locale/language output rather than offering language choice or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The line explicitly says to keep the SKILL.md body in English, which is a natural-language policy constraint. Under the stated rule, forcing a specific language without opt-in or a documented regional/compliance justification is a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

This line imposes an English-only requirement on skill documentation and reference docs. Because no user choice or clear justification is provided, it matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
59% confidence
Finding

The README links to a Chinese version, but there is no indication in this file of how language is selected or whether users can choose their preferred locale within the skill experience. This is a weak signal, but it may create ambiguity around language behavior if the skill defaults to one locale without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file presents the skill documentation entirely in Chinese while also linking to an English version, but within this document there is no user-facing statement that language is optional or selectable. Because locale/language policy violations can arise when a skill imposes a language without opt-in, this natural-language presentation may constrain users to Chinese in this variant without documenting a choice.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The configuration section requires an API_KEY, but neither the manifest description nor the rest of this file explains why a diagram-to-code skill needs external authenticated service access. For a skill whose stated purpose is transforming a provided diagram into code, this is an unjustified capability unless explicitly declared as part of the design.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.