chrisai-iconography
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes existing icon files and design system source files to inform icon creation and auditing.
- Ingestion points:
workflows/icon-creation.mdandworkflows/icon-system-audit.mddescribe inspecting local product directories, SVG files, and component wrappers. - Capability inventory: The skill has the capability to generate and write SVG files as described in
workflows/icon-creation.mdandreferences/svg-production.md. - Boundary markers: The skill does not define specific prompt delimiters for external content.
- Sanitization:
references/svg-production.mdincludes comprehensive instructions to sanitize SVG content, specifically stripping scripts, event handlers, and remote resources to prevent XSS and other injection attacks via SVG. - [EXTERNAL_DOWNLOADS]: The skill references documentation and design principles from the Lucide project and the W3C.
- Evidence:
references/lucide-profile.mdcontains links tolucide.devfor design principles and naming conventions.references/svg-production.mdcontains links tow3.orgfor accessibility guidelines. - Context: These links target well-known technology organizations and established community-standard icon libraries.
Audit Metadata