drawio-databricks
Warn
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill uses
drawio-ai scaffoldto generate a.mjsscript (build.mjs) and subsequently executes it usingnode build.mjs. This runtime code generation and execution is a medium-risk pattern as it executes newly created code. - [EXTERNAL_DOWNLOADS]: The skill requires the installation of
github:sparklabx/drawio-ai-kitvianpm i -g. While the instructions explicitly warn the agent not to perform the installation itself, the skill's core functionality depends on this external dependency sourced directly from GitHub. - [INDIRECT_PROMPT_INJECTION]: The skill provides a template for spawning subagents where the user's request is interpolated verbatim (
Request: <user's request + clarifications, verbatim>). This lacks sanitization and could allow adversarial user input to influence the subagent's logic. - Ingestion points:
SKILL.md(via subagent prompt interpolation of the user request string). - Boundary markers: Present as simple text labels (
Request:,Output:) within the subagent prompt, but there is no explicit instruction for the subagent to ignore potential command-like structures within the user data. - Capability inventory: File system writing, execution of the
drawio-aiCLI, and script execution vianode. - Sanitization: No sanitization, escaping, or validation of the user-provided request string before interpolation.
- [COMMAND_EXECUTION]: The skill orchestrates the execution of various shell commands including
drawio-ai workflow,drawio-ai principles,drawio-ai root, andnode build.mjsto perform its tasks.
Audit Metadata