bruce-drawio

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands like which and ls to detect the presence of the draw.io desktop application on various operating systems (macOS, Windows, and Linux).
  • [COMMAND_EXECUTION]: It invokes the draw.io binary with standard command-line arguments (-x, -f, -o) to perform file conversions from XML to PNG, SVG, or PDF. This is a legitimate part of the skill's core functionality.
  • [SAFE]: No network operations, data exfiltration, or access to sensitive local files (such as SSH keys or environment variables) were detected.
  • [SAFE]: No obfuscation techniques or attempts to override AI safety guidelines were found in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 07:03 PM
Security Audit — agent-trust-hub — bruce-drawio