icons-src

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents standard development procedures for adding SVG assets, updating manifest files, and running build scripts within the salesforcedx-vscode-services package. The workflow includes verification steps using existing test suites.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a process for ingesting external SVG files into the build pipeline for font generation. While processing user-provided files constitutes an attack surface (e.g., potential vulnerabilities in SVG/font parsing tools), the skill provides strict structural requirements for the XML content and targets a specific internal directory, which are standard practices for this task.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 10:07 AM
Security Audit — agent-trust-hub — icons-src