drawio-gcp
Warn
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
drawio-ai-kitfrom a third-party GitHub repositorygithub:sparklabx/drawio-ai-kit, which is not a recognized trusted organization.\n- [REMOTE_CODE_EXECUTION]: The skill instructions involve usingnpm i -gto install code directly from a GitHub repository, which allows for the execution of arbitrary installation scripts from an unverified source.\n- [COMMAND_EXECUTION]: The skill instructions involve executing several shell commands using thedrawio-aiCLI, includingworkflow,principles,search,scaffold,validate, andrendercommands.\n- [DYNAMIC_EXECUTION]: The skill implements a workflow where a JavaScript file (build.mjs) is scaffolded using the CLI tool and then executed usingnode build.mjs, involving the execution of dynamically generated code at runtime.\n- [INDIRECT_PROMPT_INJECTION]: 1. Ingestion points: User architectural requests and clarifications are interpolated directly into a prompt designed for a subagent inSKILL.md. 2. Boundary markers: The prompt uses block delimiters but lacks explicit instructions to the subagent to ignore potentially malicious commands within the interpolated user content. 3. Capability inventory: The skill and its subagents have the ability to execute shell commands (drawio-ai,node), write files to the local filesystem, and read image files. 4. Sanitization: There is no evidence of sanitization or validation of the user's input before it is passed to the subagent's prompt.
Audit Metadata