chrisai-iconography

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes existing icon files and design system source files to inform icon creation and auditing.
  • Ingestion points: workflows/icon-creation.md and workflows/icon-system-audit.md describe inspecting local product directories, SVG files, and component wrappers.
  • Capability inventory: The skill has the capability to generate and write SVG files as described in workflows/icon-creation.md and references/svg-production.md.
  • Boundary markers: The skill does not define specific prompt delimiters for external content.
  • Sanitization: references/svg-production.md includes comprehensive instructions to sanitize SVG content, specifically stripping scripts, event handlers, and remote resources to prevent XSS and other injection attacks via SVG.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation and design principles from the Lucide project and the W3C.
  • Evidence: references/lucide-profile.md contains links to lucide.dev for design principles and naming conventions. references/svg-production.md contains links to w3.org for accessibility guidelines.
  • Context: These links target well-known technology organizations and established community-standard icon libraries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 04:37 PM
Security Audit — agent-trust-hub — chrisai-iconography