Model or dataset
sparklabx/drawio-ai-kit avatar
sparklabx/drawio-ai-kit

drawio-ai-kit promises zero dependencies and ships Python, Graphviz and five vendored extras

Teach your AI to draw correct, beautiful draw.io diagrams — declarative layout engine, ground-truth stencils, structural validator, vision self-check. AWS · Azure · GCP · Databricks · BPMN. Zero dependencies.

651 stars122 forksJavaScriptMIT

At a glance

What is it?
A Node CLI plus five agent skills that make a model emit draw.io XML instead of guessing stencil IDs. The safety claims are specific and checkable, the diagram gallery is an empty tag, and the one code sample in the README ends with a stray slash.
Who is it for?
The central idea is sound and the security section is the most credible part of the page: named hooks that are absent, a dependency that was removed at a stated version, one opt-in outbound call. The weak parts are all about what a reader has to already have.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 2 days ago.
What is it written in?
Mainly JavaScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 3, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The gallery promises vision-checked diagrams and renders an empty tag

The gallery section makes five claims in one sentence: one diagram per platform, generated end to end by the kit, with no hand-placed coordinates, real stencils, validated, and vision-checked. Directly underneath is a paragraph tag with nothing in it:

code
<p align="center"></p>

No image, no caption, no link beyond the pointer to `examples/`. So the evidence for the strongest claim in the README, that the validation and vision loop works end to end on real architectures, is deferred to the example scripts rather than shown. The claim itself is checkable by running them, since each example writes to `out/*.drawio`, but a reader scanning the page sees an assertion followed by an empty element.

Zero dependencies describes the runtime, not the package

The safety section says the package has zero runtime dependencies, that the single dependency, `@modelcontextprotocol/sdk`, was removed at 1.0.0, and that nothing runs on install because there are no lifecycle hooks. All of that is about the Node process. The published file list is longer than that claim:

code
"files": [
    "src",
    "catalog",
    "data",
    "rules",
    "vendor",
    "scripts",
    "examples",
    "skills"
  ],

A `vendor` directory ships in the tarball, and the quick start names `vendor/autolayout.py` as the large-graph layout path that needs Graphviz. The npm scripts also include `gen:catalog`, which runs `python3.11 scripts/ingest_index.py`, and the repository root carries `.python-version` and a `.semgrepignore`. The declared engine constraint is only `node >=18`, so a Node-only reader has no warning that two of the documented paths need other tools.

The vision self-check depends on the draw.io desktop app

The agent loop is described as render, analyze, rectify: the model defines the logical layout, the engine renders, and the model looks at the result and corrects itself. Migration notes make the render step concrete, replacing an inline image with `drawio-ai render`, then a PNG, then a `Read`. That PNG has to come from somewhere, and the quick start says the draw.io desktop app is what enables the render command, listed as optional for the full experience. Graphviz is the second optional dependency, enabling `vendor/autolayout.py` for large graphs. So the self-correcting loop that justifies the vision-checked claim in the gallery needs an external GUI application installed locally, and the page offers no headless substitute.

The default install tracks the branch tip while skills update separately

Nothing is on the npm registry yet, so installation goes straight from GitHub:

bash
npm i -g github:sparklabx/drawio-ai-kit && npx skills add sparklabx/drawio-ai-kit

That form installs the default branch, not a release, which is why the page explains pinning with a tag fragment such as `github:sparklabx/drawio-ai-kit#v1.0.1` and points to INSTALL.md for clones. Updates then run through two channels, with `npm i -g github:sparklabx/drawio-ai-kit` for the CLI and `npx skills update` for the domain skills. The reasoning behind that split is stated plainly: the skills are thin frontends that call `drawio-ai` at runtime, so engine fixes land the moment the CLI updates, and the skills command only refreshes SKILL.md text. The consequence is that a pinned skill and an unpinned engine, or the reverse, are both ordinary states.

The layout example ends with a lone slash and imports from source paths

The README shows one JavaScript sample, and it is the only API documentation. It opens with relative imports, `import { Diagram } from "./src/builder.mjs"`, which assumes a clone rather than the global npm install. It closes like this:

js
renderTree(d, tree);                 // engine lays everything out + sizes the page
d.title("My VPC");
d.link("alb", "ec2");                // edges by id; router picks straight/corridor
const res = d.validate();            /

The last line assigns the validation result to a variable nothing then uses, and it ends with a slash rather than a comment or a statement, so copying the block produces a syntax error on the final line. The rest of the sample is the interesting part: a topology name from the list of seven, nested groups with a direction, icons resolved by id, and a router that chooses between straight and corridor edges. The validator call itself is where the promise of the tool lives, and it is the line that does not parse.

Six example folders, five domain skills, and a list that stops mid-word

The template library is organised into domain subfolders. The AWS table is the detailed one, twelve scripts with their topology type and architecture named: a layered analytics pipeline, a landing zone, a multi-AZ three-tier VPC, VPC routing, EKS with bastion and NAT, EFS with a mount target per availability zone, an event bus, a serverless request walkthrough, Direct Connect with mirrored disaster recovery, a service mesh, and multi-account IAM. Then the remaining folders are named in a single line that stops partway through the last word, after `databricks/` and the letters `mult`. So the count is six folders on disk, including a multicloud one, while the skills that drive them number five: AWS, Azure, GCP, Databricks and BPMN. The multicloud examples have no domain skill behind them.

The catalog is generated by a Python script, not typed in by hand

The failure this kit targets is specific: a model invents a stencil identifier such as an `mxgraph.aws4.*` name that does not exist, and the diagram renders with an empty shape where an icon should be. Three components answer it. The declarative catalog maps stencil IDs to their taxonomies and canonical colour palettes. The design principles live in `rules/principles.md`. The structural validator is a static analysis pass over diagram XML that checks stencil references and principle compliance before serialization. None of the three is maintained by typing. The npm script `gen:catalog` runs `python3.11 scripts/ingest_index.py`, which regenerates the catalog and data directories from an index, and the agent is told to look names up with `drawio-ai search` instead of recalling them.

Version 1.0.0 deleted the MCP server and the bespoke installer

The migration section is the clearest statement of what changed and when. At 1.0.0 the MCP server and the bespoke installer were removed. Installation moved from `claude mcp add ... mcp-server.mjs` to the npm global install, the old `drawio-cloud-architect` skill was replaced by the five thin domain skills, and the inline image gave way to the render command. The three published tags line up with that story: v1.0.0 is labelled CLI-only and dated 10 July 2026, v1.0.1 carries search and workflow fixes, and v1.0.2 carries compact layouts and cleaner edges on 4 August 2026. The branch has been pushed to as late as 10 September 2026, so the current source is ahead of the newest tag. The uninstall snippet that closes the safety section also lists two commands whose trailing comments do not line up with each other.

Editorial conclusion

The central idea is sound and the security section is the most credible part of the page: named hooks that are absent, a dependency that was removed at a stated version, one opt-in outbound call. The weak parts are all about what a reader has to already have. Rendering for the vision self-check needs the draw.io desktop app, large-graph layout needs Graphviz, catalog regeneration needs Python 3.11, and the layout example imports relative source paths, so the npm-only install supports a subset of what the README shows. Before adopting it, check which of those you have, and pin the CLI by tag rather than installing from the default branch, since `npm i -g github:...` tracks the branch tip while the skills update on a separate channel. It suits an agent-driven workflow where someone supervises each diagram. It does not suit a pipeline that needs pinned, reproducible installs without an external desktop app.

Frequently asked questions

What is drawio-ai-kit?

A Node package published as the `drawio-ai` command plus five agent skills, MIT licensed and requiring Node 18 or later. It gives a model three things: a catalog mapping draw.io stencil IDs to taxonomies and colour palettes, codified layout rules in `rules/principles.md`, and a validator that audits diagram XML before it is written. Its target failure is a model inventing a stencil ID and producing an empty shape.

Is drawio-ai-kit safe to install?

The page argues the case itself: no lifecycle or postinstall hooks, zero runtime dependencies after `@modelcontextprotocol/sdk` was removed at 1.0.0, no sudo and no piped shell script, and one opt-in outbound call for icon logos from public CDNs. Two caveats sit beside those claims. It installs straight from GitHub rather than the npm registry, and the published files include a `vendor` directory plus a Python script for Graphviz layout.

Can an assistant such as ChatGPT produce a draw.io diagram with drawio-ai-kit?

The kit does not call a model itself. It is built for an agent that can run shell commands and read files: the model builds a topology through the layout engine, `drawio-ai render` produces a PNG, and the model reads that image back to correct itself. The README frames this as Claude Code, Codex and Gemini CLI style usage through the `skills` CLI.

How do I pin a version of drawio-ai-kit?

Since the package is not on the npm registry, the install specifier carries the tag, for example `github:sparklabx/drawio-ai-kit#v1.0.1`, and INSTALL.md covers pinning or installing from a clone. Skills are a separate channel updated with `npx skills update`, which only refreshes SKILL.md text, while the skills themselves call the CLI at runtime.

Official sources

  1. Issues
  2. License: MIT
  3. README
  4. Releases
  5. sparklabx/drawio-ai-kit on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/sparklabx-drawio-ai-kit.svg)](https://hysenlabs.com/projects/sparklabx-drawio-ai-kit)