drawio-databricks

Warn

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill uses drawio-ai scaffold to generate a .mjs script (build.mjs) and subsequently executes it using node build.mjs. This runtime code generation and execution is a medium-risk pattern as it executes newly created code.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of github:sparklabx/drawio-ai-kit via npm i -g. While the instructions explicitly warn the agent not to perform the installation itself, the skill's core functionality depends on this external dependency sourced directly from GitHub.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a template for spawning subagents where the user's request is interpolated verbatim (Request: <user's request + clarifications, verbatim>). This lacks sanitization and could allow adversarial user input to influence the subagent's logic.
  • Ingestion points: SKILL.md (via subagent prompt interpolation of the user request string).
  • Boundary markers: Present as simple text labels (Request:, Output:) within the subagent prompt, but there is no explicit instruction for the subagent to ignore potential command-like structures within the user data.
  • Capability inventory: File system writing, execution of the drawio-ai CLI, and script execution via node.
  • Sanitization: No sanitization, escaping, or validation of the user-provided request string before interpolation.
  • [COMMAND_EXECUTION]: The skill orchestrates the execution of various shell commands including drawio-ai workflow, drawio-ai principles, drawio-ai root, and node build.mjs to perform its tasks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 10, 2026, 10:56 AM
Security Audit — agent-trust-hub — drawio-databricks