| Version | Supported |
|---|---|
| latest | ✅ |
This project is a skill file (markdown + reference data) with no runtime code, network access, or dependencies. The attack surface is minimal.
If you discover a security issue (for example, a reference file that could cause an agent to generate malicious output), please report it responsibly:
- Do not open a public issue.
- Email vidanov@gmail.com with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- You will receive acknowledgment within 72 hours.
- A fix will be released as soon as possible, and you will be credited (unless you prefer otherwise).
Security concerns relevant to this project:
- Prompt injection via reference files
- Stencil names that could trigger unintended behavior in draw.io
- Supply chain concerns with the
npx skills addinstallation method
- Vulnerabilities in draw.io itself
- Vulnerabilities in AI agents consuming this skill
- Issues with the user's local environment