drawio

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Benign. The skill focuses on local, user-driven diagram generation and export via the draw.io desktop CLI with explicit, user-controlled workflows. There are no credential requirements, no remote data transfers, and no execution of untrusted binaries or pipelines. The data flow is confined to the user’s machine (input prompts → local .drawio XML → local exports). The only potential risk is if the user inadvertently runs imports/exports with untrusted files, but this is inherent to any diagramming workflow and not a security flaw in the skill design itself.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 12:47 PM
Package URL
pkg:socket/skills-sh/agents365-ai%2Fdrawio-skill%2Fdrawio%2F@63c98acae3c9038dd3bd057f5b7d02dfa41a2e0b