fireworks-tech-graph
Pass
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to executersvg-convertandpython. To mitigate risk, the instructions explicitly command the agent to quote file paths when invoking shell commands, which prevents command injection vulnerabilities that could otherwise occur through malicious file naming in the user-provided arguments. - [SAFE]: The skill instructions and reference files (specifically
icons.mdand the style guides) explicitly forbid the use of external@importstatements or remote URLs for fonts and assets. This is a critical security control that prevents Server-Side Request Forgery (SSRF) and data exfiltration through the SVG conversion process. - [EXTERNAL_DOWNLOADS]: Although the
allowed-toolsconfiguration includescurl, the skill's actual workflow is entirely local, using provided reference files within the skill directory rather than fetching external content from the internet. - [DATA_EXFILTRATION]: The skill lacks any patterns of reading sensitive system files (e.g.,
.ssh,.env) or exfiltrating data to external domains. File operations are restricted to reading style references and writing the resulting diagram artifacts.
Audit Metadata