excalidraw

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external .excalidraw and .excalidraw.json files which present a surface for indirect prompt injection via text labels. Ingestion points: Subagent tasks for reading diagram files in SKILL.md and README.md. Boundary markers: Instructions in SKILL.md to avoid returning raw JSON and to provide text-only summaries. Capability inventory: File read, modify, and create capabilities described in SKILL.md. Sanitization: Instructions to extract only text labels while ignoring styling and metadata provide a form of content filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:12 PM
Security Audit — agent-trust-hub — excalidraw