Back to skill

Security audit

drawio-flowchart

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed draw.io flowchart generator with only expected local file creation and no evidence of hidden, destructive, or data-exfiltrating behavior.

Install this if you want an agent to create draw.io flowchart files. Expect it to write a local .drawio file in the workspace or a path you specify, and review the filename/path before saving. Non-Chinese users may want to ask the agent to use their preferred language for diagram labels and responses.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (10)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

Fan-out pattern (one source → multiple targets)

Use explicit entry points to prevent crossing:

xml
<!-- Left target: entryX=0.25 -->
style="...entryX=0.25;entryY=0;exitX=0.5;exitY=1;"
<!-- Center target: entryX=0.5 -->
style="...entryX=0.5;entryY=0;exitX=0.5;exitY=1;"

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

xml
<!-- Left target: entryX=0.25 -->
style="...entryX=0.25;entryY=0;exitX=0.5;exitY=1;"
<!-- Center target: entryX=0.5 -->
style="...entryX=0.5;entryY=0;exitX=0.5;exitY=1;"
<!-- Right target: entryX=0.75 -->
style="...entryX=0.75;entryY=0;exitX=0.5;exitY=1;"

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

style="...entryX=0.25;entryY=0;exitX=0.5;exitY=1;"

style="...entryX=0.5;entryY=0;exitX=0.5;exitY=1;"

style="...entryX=0.75;entryY=0;exitX=0.5;exitY=1;"

text

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/template.md (reported line 16)May include surrounding context.

md
<mxCell id="0" />
        <mxCell id="1" parent="0" />

        <!-- ===== Title ===== -->
        <mxCell id="title" parent="1"
          style="text;html=1;align=center;verticalAlign=middle;
                 fontSize=24;fontStyle=1;fontColor=#111111;"

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/template.md (reported line 89)May include surrounding context.

md
<mxGeometry relative="1" as="geometry" />
        </mxCell>

        <!-- ===== Stage 2 Container ===== -->
        <mxCell id="g2" parent="1" connectable="0"
          style="swimlane;startSize=32;fillColor=#F0FDF4;
                 strokeColor=#16a34a;strokeWidth=2;fontSize=14;

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill hardcodes Chinese-language output and delivery instructions regardless of the user's language or preferences. This can override user intent and create instruction-priority conflicts, causing unexpected behavior and reducing transparency in agent responses.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The main skill description is presented entirely in Chinese and does not indicate that other languages are supported or that the user may choose their preferred language. Under SQP-3, forcing a specific language without user opt-in can be a natural-language policy concern unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The markdown explicitly says the skill will generate a complete .drawio XML file and save it locally. For markdown files, SQP-2 applies when the skill description omits warnings about behaviors that could affect user data or system integrity; this section describes a local file write but does not include any caution or disclosure about where the file will be created or that it modifies the user's filesystem.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template includes a hard-coded Chinese placeholder text ("流程图标题") for the diagram title. Because this is a general template rather than a clearly region-specific artifact, it imposes a specific language choice in the natural-language content without offering alternatives or documenting that constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The section describing parallel options instructs use of the label "或", which is a Chinese-language term. In a generic template file, this constitutes a locale-specific natural-language choice without user opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.