跳到主要内容
知仓学习社ZHICANG

drawio

Generate draw.io diagrams as .drawio files and export to PNG/SVG/PDF with embedded XML

执行命令写文件读文件联网读环境变量(配置)严重 0 · 高危 7github/awesome-copilot

它会碰到什么

扫了多少3 个文本文件,15 KB
它会碰到什么执行命令写文件读文件联网读环境变量(配置)
命中总数12 处
命中统计严重 0 · 高 7 · 中 4 · 低 1

关于「读环境变量(配置)」:这个技能会读 process.env 之类的环境变量,但读到的都是端口、目录、超时这类配置项,没有读取密钥类变量。扫描规则原本把「读环境变量」一律算作「读凭据」,本站按变量名做了细化区分,命中明细仍如实列在下面。

逐条看命中(7 条严重或高危)
  • scripts/drawio-to-png.mjs:15exec-spawn
    import { spawnSync } from "child_process";
  • scripts/drawio-to-png.mjs:15exec-spawn
    import { spawnSync } from "child_process";
  • scripts/drawio-to-png.mjs:160cred-envread
    const envPath = process.env.DRAWIO_PATH;
  • scripts/drawio-to-png.mjs:185exec-spawn
    const probe = spawnSync(locator, [name], { encoding: "utf-8" });
  • scripts/drawio-to-png.mjs:197exec-spawn
    const result = spawnSync(drawioPath, args, { encoding: "utf-8" });
  • scripts/drawio-to-png.mjs:265cred-envread
    process.env.CHROME_PATH,
  • scripts/drawio-to-png.mjs:266cred-envread
    process.env.EDGE_PATH,

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Draw.io Diagram Skill

Generate draw.io diagrams as native .drawio files and export them to PNG images that can be embedded in Word documents.

How to Create a Diagram

  1. Generate draw.io XML in mxGraphModel format for the requested diagram
  2. Write the XML to a .drawio file using the create/edit file tool
  3. Export to PNG using the bundled export script

Bundled Export Script

This skill includes drawio-to-png.mjs, a Node.js export script with two rendering backends:

  1. draw.io CLI (pixel-perfect, fastest) — used automatically if draw.io desktop is installed
  2. Official draw.io viewer in headless browser (pixel-perfect, needs Chromium/Edge) — fallback when CLI is unavailable

Usage

# Install dependencies (one-time, from the scripts folder)
cd skills/drawio/scripts && npm install

# Export a single diagram
node skills/drawio/scripts/drawio-to-png.mjs <input.drawio> [output.png]

# Export all .drawio files in a directory
node skills/drawio/scripts/drawio-to-png.mjs --dir <directory>

# Force a specific renderer
node skills/drawio/scripts/drawio-to-png.mjs --renderer=cli|viewer|auto <input.drawio>

Skill Folder Contents

| File | Purpose |

|------|---------|

| SKILL.md | This instruction file |

| scripts/drawio-to-png.mjs | Node.js export script (CLI + browser fallback) |

| scripts/package.json | Dependencies (puppeteer-core) |

Supported Export Formats

| Format | Embed XML | Notes |

|--------|-----------|-------|

| png | Yes | Viewable everywhere, editable in draw.io |

| svg | Yes | Scalable, editable in draw.io |

| pdf | Yes | Printable, editable in draw.io |

Draw.io XML Style Conventions

Use these styles for consistent, professional diagrams:

<!-- Primary service (highlighted) -->
<mxCell style="rounded=1;whiteSpace=wrap;html=1;fillColor=#dae8fc;strokeColor=#6c8ebf;strokeWidth=2;arcSize=12;shadow=1;" />

<!-- External system -->
<mxCell style="rounded=1;whiteSpace=wrap;html=1;fillColor=#f5f5f5;strokeColor=#666666;" />

<!-- Success/processing stage -->
<mxCell style="rounded=1;whiteSpace=wrap;html=1;fillColor=#d5e8d4;strokeColor=#82b366;" />

<!-- Warning/quality gate -->
<mxCell style="rounded=1;whiteSpace=wrap;html=1;fillColor=#fff2cc;strokeColor=#d6b656;" />

<!-- Error/failure path -->
<mxCell style="rounded=1;whiteSpace=wrap;html=1;fillColor=#f8cecc;strokeColor=#b85450;" />

<!-- Data store (cylinder) -->
<mxCell style="shape=cylinder3;whiteSpace=wrap;html=1;fillColor=#fff2cc;strokeColor=#d6b656;" />

<!-- Arrow -->
<mxCell style="edgeStyle=orthogonalEdgeStyle;rounded=1;strokeColor=#6c8ebf;strokeWidth=2;" />

Locating the draw.io CLI

Try drawio first (works if on PATH), then fall back:

  • Windows: "C:\Program Files\draw.io\draw.io.exe"
  • macOS: /Applications/draw.io.app/Contents/MacOS/draw.io
  • Linux: drawio (via snap/apt/flatpak)

CLI Export Command

drawio -x -f png -e -b 10 -o <output.png> <input.drawio>

Flags: -x (export), -f (format), -e (embed diagram XML), -b (border), -o (output path).

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。