processon-diagram-generator
Warn
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The
setup.mjsscript contains a hardcoded template (nodeSpawnHttpScript) containing logic for HTTP requests and JSON parsing. This template is dynamically executed at runtime usingspawn(process.execPath, ["-e", ...])as a fallback mechanism to invoke the ProcessOn MCP tool if standard methods fail. - [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The
SKILL.mdfile mandates a pre-execution check usingnode -eto fetch and parse a version file fromraw.githubusercontent.com. While the source is a well-known service associated with the skill author, this pattern allows remote data to influence execution flow at load time. - [COMMAND_EXECUTION]: The skill makes extensive use of shell commands via
run_shell_commandand a wrappersetup.mjsscript to manage authentication flows, token polling, and tool invocation. These commands interact with local configuration files and environment variables. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill implements a persistence mechanism for authentication tokens, reading and writing to
~/.processon-diagram-generator/token.jsonand using the user's home directory to store sensitive Bearer tokens. - [PROMPT_INJECTION]: The
SKILL.mdfile contains forceful directives (e.g., "【强制触发】", "【禁止绕过】") and English equivalents like "Do not skip this skill" intended to override the agent's default tool selection logic in favor of this specific skill.
Audit Metadata