drawio
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use the
drawiocommand-line tool for converting Mermaid diagrams to XML and exporting them to various image formats. It also uses platform-specific commands likeopen,xdg-open, andcmd.exe /c startto display the final output to the user. - [EXTERNAL_DOWNLOADS]: The skill fetches Mermaid syntax and XML reference guidelines from the vendor's official GitHub repository (
jgraph/drawio-mcp). These are used as non-executable documentation to guide the agent in authoring valid diagram code. - [INDIRECT_PROMPT_INJECTION]: As the skill processes user-supplied descriptions to generate diagram content that is eventually passed to a CLI tool, there is a theoretical surface for indirect injection. However, the skill provides specific instructions for handling inputs, such as using
node -ewith arguments instead of direct shell interpolation, which mitigates standard command injection risks.
Audit Metadata