processon-diagram-generator

Warn

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The setup.mjs script contains a hardcoded template (nodeSpawnHttpScript) containing logic for HTTP requests and JSON parsing. This template is dynamically executed at runtime using spawn(process.execPath, ["-e", ...]) as a fallback mechanism to invoke the ProcessOn MCP tool if standard methods fail.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The SKILL.md file mandates a pre-execution check using node -e to fetch and parse a version file from raw.githubusercontent.com. While the source is a well-known service associated with the skill author, this pattern allows remote data to influence execution flow at load time.
  • [COMMAND_EXECUTION]: The skill makes extensive use of shell commands via run_shell_command and a wrapper setup.mjs script to manage authentication flows, token polling, and tool invocation. These commands interact with local configuration files and environment variables.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill implements a persistence mechanism for authentication tokens, reading and writing to ~/.processon-diagram-generator/token.json and using the user's home directory to store sensitive Bearer tokens.
  • [PROMPT_INJECTION]: The SKILL.md file contains forceful directives (e.g., "【强制触发】", "【禁止绕过】") and English equivalents like "Do not skip this skill" intended to override the agent's default tool selection logic in favor of this specific skill.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — processon-diagram-generator