ios-icon-gen
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads icon assets in SVG format from
https://api.iconify.design. This is a well-known and widely used service for open-source icon collections. The downloaded files are used as source material for image conversion and are not executed as code. - [COMMAND_EXECUTION]: The skill utilizes several local command-line tools to perform its tasks. It uses
curlfor fetching remote assets,sips(a built-in macOS utility) for converting SVG files to PNG, andpython3one-liners for URL encoding and JSON parsing of API responses. These operations are standard for the skill's stated purpose of icon generation. - [INDIRECT_PROMPT_INJECTION]: The skill fetches and displays search results and collection metadata from a remote API, which constitutes an indirect prompt injection surface.
- Ingestion points: Icon search results and collection lists retrieved via
scripts/iconify_gen.shfrom the Iconify API. - Boundary markers: Not present. The agent processes the raw output from the shell script.
- Capability inventory: The skill can write to the local filesystem (
mkdir,sips, shell redirection) and perform network requests (curl). - Sanitization: The script employs Python's
jsonmodule to parse API responses, ensuring that the structure is correctly handled, though the content itself is treated as trusted text by the agent.
Audit Metadata