drawio-azure
Warn
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to install a global package from a specific GitHub repository ('github:sparklabx/drawio-ai-kit'). While it explicitly warns the agent not to perform the installation itself, it remains a dependency on unverifiable code from an external, non-official source.
- [DYNAMIC_EXECUTION]: The skill uses a workflow where a JavaScript file ('build.mjs') is scaffolded by a CLI tool and subsequently executed via 'node build.mjs'. This represents the generation and execution of code at runtime based on user-defined requirements.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data within a subagent environment, creating a potential surface for indirect prompt injection.
- Ingestion points: User requests and clarifications are passed verbatim into a subagent prompt in 'SKILL.md'.
- Boundary markers: None identified; the user's request is interpolated directly into the instructions.
- Capability inventory: The skill can execute shell commands via 'drawio-ai', write files to the filesystem, and run JavaScript via 'node' (found in 'SKILL.md').
- Sanitization: No evidence of input validation or escaping before interpolation into the build script or CLI commands.
- [COMMAND_EXECUTION]: The skill frequently invokes shell commands ('drawio-ai', 'node', 'command -v') to perform its primary function. This involves running logic through subprocesses, which could be exploited if the inputs to those commands are manipulated.
Audit Metadata