bruce-drawio
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands like
whichandlsto detect the presence of the draw.io desktop application on various operating systems (macOS, Windows, and Linux). - [COMMAND_EXECUTION]: It invokes the draw.io binary with standard command-line arguments (
-x,-f,-o) to perform file conversions from XML to PNG, SVG, or PDF. This is a legitimate part of the skill's core functionality. - [SAFE]: No network operations, data exfiltration, or access to sensitive local files (such as SSH keys or environment variables) were detected.
- [SAFE]: No obfuscation techniques or attempts to override AI safety guidelines were found in the instructions.
Audit Metadata