draw-io-diagram-generator

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes Python utility scripts (validate-drawio.py and add-shape.py) for validating diagram structure and adding shapes. These scripts are intended for local execution using the Python standard library and do not involve network requests, remote code execution, or arbitrary command execution.
  • [DATA_EXFILTRATION]: The utility scripts perform local file read and write operations on .drawio files provided as command-line arguments. There are no network operations or hardcoded credentials that would facilitate data exfiltration or credential theft.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external .drawio (mxGraph XML) files. The utility scripts perform structural validation (checking IDs and XML well-formedness) and do not interpret file content as executable instructions, maintaining a safe execution boundary.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:13 AM