drawio-skill

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of the subprocess module to interact with local system utilities required for its operation. This includes executing the drawio (or draw.io) binary for exporting diagrams to various image formats, dot and tred from the Graphviz suite for auto-layout and transitive reduction of graphs, and git for accessing repository history to generate architecture time-lapses. These operations are core to the skill's functionality and are restricted to the local environment.
  • [EXTERNAL_DOWNLOADS]: The script scripts/aiicons.py fetches AI/LLM brand logo SVGs from well-known and reputable content delivery networks, specifically unpkg.com (for lobe-icons) and cdn.simpleicons.org. This behavior is documented and intended for providing branded iconography in generated diagrams.
  • [DYNAMIC_EXECUTION]: Several utility scripts within the skill (scripts/c4.py, scripts/edgeports.py, scripts/restyle.py, scripts/tfimports.py, and scripts/tfstate.py) use importlib.util to dynamically load sibling Python modules (like validate.py or autolayout.py). This is used for code reuse across the bundled toolset and is limited to local files shipped with the skill.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill includes importers that read local project data, such as docker inspect output (dockerimports.py) and Terraform state files (tfstate.py), to visualize infrastructure. The information processed by these scripts is utilized locally to generate graph JSON for diagram creation and is not sent to external servers.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — drawio-skill