automating-excalidraw
Warn
Audited by Socket on Apr 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The overall skill purpose is coherent and the file/network actions largely match Excalidraw automation, with no credential harvesting or overtly malicious behavior. Risk comes from an unverified @excalidraw/cli reference and browser-based export that sends diagram data to the live excalidraw.com app, making this a medium-risk documentation/integration skill rather than confirmed malware.
Confidence: 89%Severity: 52%
Audit Metadata