Back to skill

Security audit

Draw.io Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for draw.io diagram work, but its setup recommends running an unpinned third-party MCP server and it can be invoked broadly, so it should be reviewed before installation.

Review the MCP server package before installing, prefer a pinned reviewed version instead of `@latest`, and run it with only the filesystem and network access needed for diagram work. Be aware that this skill may auto-activate for broad diagram requests and can create or modify exported diagram files in the workspace.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:76
Finding

Unpinned Third-Party MCP Server Package Is Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: README.md:76
Vulnerability Type: Unpinned dependency execution and supply-chain exposure
Risk Level: Medium

Vulnerable Code Snippet:

bash
codex mcp add drawio -- npx -y @next-ai-drawio/mcp-server@latest

Technical Analysis

The documented installation command uses npx with the mutable @latest tag and the -y option. This causes npm to retrieve and execute whichever release is identified as the latest version at installation time, without requiring interactive confirmation.

Because neither an exact package version nor an integrity value is specified, the executed code can differ from the code that was available when this skill was audited. This weakens reproducibility and creates a supply-chain trust boundary around the npm package, its maintainers, the associated publishing account, the npm registry, and its transitive dependencies.

The audit found no evidence that the currently named package is malicious. The vulnerability is the unsafe dependency acquisition pattern: a future compromised, malicious, or unexpectedly incompatible release could be downloaded and executed automatically.

Attack Path

  1. An attacker compromises the npm package, a maintainer or publishing account, the package namespace, or a transitive dependency.
  2. The attacker publishes a malicious version that becomes the target of the latest distribution tag.
  3. A user follows the setup instructions in README.md.
  4. npx -y downloads the attacker-controlled release without requesting package-installation confirmation.
  5. npm installation hooks or the MCP server entry point execute with the privileges of the user running Codex.
  6. Malicious code can access resources available to that account and may continue operating whenever the configured MCP server is subsequently launched.

Impact Assessment

Successful exploitation could provide arbitrary code execution under t ...[truncated 587 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an exact, reviewed package version, for example:

    bash
    codex mcp add drawio -- npx -y @next-ai-drawio/mcp-server@X.Y.Z
    

    Substitute X.Y.Z with a version that has been independently reviewed and tested.

  2. Document the package's authoritative source repository and npm publisher so users can verify provenance before installation.

  3. Maintain a lockfile or another integrity-controlled installation mechanism where the surrounding deployment model supports it. Pin transitive dependencies and verify registry integrity metadata.

  4. Review package lifecycle scripts and the MCP server entry point before approving version upgrades. Treat each upgrade as a new code-execution trust decision.

  5. Avoid recommending automatic acceptance through npx -y where interactive review is practical. If -y remains necessary for automation, pair it with exact version pinning and integrity verification.

  6. Run the MCP server with least privilege in an isolated environment. Restrict filesystem and network access to the minimum required for diagram operations.

  7. Establish a controlled update process that tests and approves newer versions before changing the documented pin.

Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states the skill is designed for 'Chinese labels and Chinese output,' and later describes 'Chinese labeling' as part of the skill rules. This reads as a locale/language constraint built into the skill behavior, but the document does not indicate that users can opt in or choose another language.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 34)May include surrounding context.

md
这个 Skill 会告诉 Codex 如何以稳定的流程使用 draw.io MCP server:

1. start a draw.io session
2. create diagrams from full XML
3. read the current diagram before editing
4. export editable and shareable outputs

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README lists 'Chinese labeling' under the rules the skill includes, which suggests the skill may enforce a specific language policy by default. Because no alternative language option or opt-in mechanism is described, this may violate the requirement not to force a locale without user choice.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to install and run an MCP server package via npx using the latest published version, which creates a supply-chain risk. If the package is compromised or a breaking/malicious update is published, users may execute unreviewed code in their local environment when following the documented setup.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The 'Good triggers' section includes generic phrases such as 'Edit this flowchart', 'Turn this process into a draw.io diagram', and 'Map a deployment topology' that could match ordinary conversation or requests intended for other tools. The file does not provide exclusion conditions or boundaries explaining when these phrases should not activate this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill enables implicit invocation without any scoped trigger conditions or user-confirmation boundaries, allowing the agent to auto-select a draw.io MCP tool in broader contexts than users may expect. Because this tool can create, edit, and export files through an external MCP server, unintended invocation could cause unauthorized diagram modification, data leakage into generated artifacts, or surprising side effects from natural-language requests that merely mention diagrams.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.