drawio-skill
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of the
subprocessmodule to interact with local system utilities required for its operation. This includes executing thedrawio(ordraw.io) binary for exporting diagrams to various image formats,dotandtredfrom the Graphviz suite for auto-layout and transitive reduction of graphs, andgitfor accessing repository history to generate architecture time-lapses. These operations are core to the skill's functionality and are restricted to the local environment. - [EXTERNAL_DOWNLOADS]: The script
scripts/aiicons.pyfetches AI/LLM brand logo SVGs from well-known and reputable content delivery networks, specificallyunpkg.com(for lobe-icons) andcdn.simpleicons.org. This behavior is documented and intended for providing branded iconography in generated diagrams. - [DYNAMIC_EXECUTION]: Several utility scripts within the skill (
scripts/c4.py,scripts/edgeports.py,scripts/restyle.py,scripts/tfimports.py, andscripts/tfstate.py) useimportlib.utilto dynamically load sibling Python modules (likevalidate.pyorautolayout.py). This is used for code reuse across the bundled toolset and is limited to local files shipped with the skill. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill includes importers that read local project data, such as
docker inspectoutput (dockerimports.py) and Terraform state files (tfstate.py), to visualize infrastructure. The information processed by these scripts is utilized locally to generate graph JSON for diagram creation and is not sent to external servers.
Audit Metadata