create-svg

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill utilizes Playwright to launch a headless Chromium instance for verifying SVG animations. This rendering process is secured by a multi-layered validation pipeline that scans the SVG for malicious content before execution.
  • [SAFE]: Structural validation in validate.py explicitly identifies and rejects active content tags (such as <script>, <foreignObject>, and <iframe>), JavaScript event handlers, and external network references in both XML and CSS declarations.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill uses defusedxml for all SVG and XML parsing, effectively mitigating risks associated with XML External Entity (XXE) and billion laughs (quadratic expansion) attacks.
  • [COMMAND_EXECUTION]: Execution is managed via run.sh and uv run, providing environment isolation. The shutil.which utility is used to locate system browser executables for verification tasks.
  • [EXTERNAL_DOWNLOADS]: The sanity.sh script performs environment synchronization using uv sync, fetching dependencies from the official PyPI registry to ensure a consistent and updated runtime.
  • [SAFE]: Input data and configuration are processed using yaml.safe_load and strictly validated against Pydantic models with extra="forbid" settings, preventing unexpected behavior or malicious object construction.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — create-svg