recreate-scientific-figure-in-drawio

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses specific, restricted tools for drawing within the draw.io application. It explicitly forbids operating system-level automation and pre-building XML, requiring a step-by-step recreation process that enhances transparency for the user.
  • [PROMPT_INJECTION]: Surface analysis for indirect injection via visual inputs. Ingestion points: Reference images and PDF files provided by the user (SKILL.md). Boundary markers: No explicit instructions are provided to the agent to ignore or delimit potentially malicious text contained within the source images. Capability inventory: The agent has access to specialized tools for drawing and file-writing (drawio_live_save_snapshot, drawio_export) to save resulting diagrams. Sanitization: The skill does not define methods for sanitizing text or instructions extracted from reference materials via vision.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — recreate-scientific-figure-in-drawio