excalidraw
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external .excalidraw and .excalidraw.json files which present a surface for indirect prompt injection via text labels. Ingestion points: Subagent tasks for reading diagram files in SKILL.md and README.md. Boundary markers: Instructions in SKILL.md to avoid returning raw JSON and to provide text-only summaries. Capability inventory: File read, modify, and create capabilities described in SKILL.md. Sanitization: Instructions to extract only text labels while ignoring styling and metadata provide a form of content filtering.
Audit Metadata