tldraw-skill

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands to manage dependencies, create directories, and render diagrams. Specifically, it uses tldraw --version, mkdir -p, and the tldraw export utility. It also utilizes OS-specific commands (open, xdg-open, start) to launch generated files for the user.
  • [EXTERNAL_DOWNLOADS]: The instructions direct the agent to install the @kitschpatrol/tldraw-cli package globally via npm and download browser binaries using npx puppeteer to support the rendering process.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes untrusted user descriptions to generate diagram labels and structure, and uses vision capabilities to analyze the resulting images.
  • Ingestion points: User-provided text describing diagram requirements and the content of generated image files (PNG) during the self-check phase.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat user-provided text as data rather than instructions when generating the diagram JSON.
  • Capability inventory: Capability to write to the file system, create directories, and execute the tldraw CLI and browser-based export tools.
  • Sanitization: The skill does not define methods for sanitizing or escaping user-provided strings before they are interpolated into the props.text fields of the .tldr JSON file.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — tldraw-skill