excalidraw-mcp-drawing
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions and associated Python script (
scripts/fix_bindings.py) follow safe practices for managing local diagram data. - [COMMAND_EXECUTION]: The skill provides a script to be executed locally by the agent to post-process Excalidraw JSON files. The script uses standard libraries (
json,pathlib) to modify specific fields within the JSON structure and does not perform network operations or access sensitive system files. - [DATA_EXPOSURE]: The skill handles diagram data and Excalidraw collaboration URLs. It includes explicit instructions for the agent to ask the user for the collaboration URL rather than guessing or reusing old ones, which is a good privacy practice.
Audit Metadata