create-svg
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The skill utilizes Playwright to launch a headless Chromium instance for verifying SVG animations. This rendering process is secured by a multi-layered validation pipeline that scans the SVG for malicious content before execution.
- [SAFE]: Structural validation in
validate.pyexplicitly identifies and rejects active content tags (such as<script>,<foreignObject>, and<iframe>), JavaScript event handlers, and external network references in both XML and CSS declarations. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill uses
defusedxmlfor all SVG and XML parsing, effectively mitigating risks associated with XML External Entity (XXE) and billion laughs (quadratic expansion) attacks. - [COMMAND_EXECUTION]: Execution is managed via
run.shanduv run, providing environment isolation. Theshutil.whichutility is used to locate system browser executables for verification tasks. - [EXTERNAL_DOWNLOADS]: The
sanity.shscript performs environment synchronization usinguv sync, fetching dependencies from the official PyPI registry to ensure a consistent and updated runtime. - [SAFE]: Input data and configuration are processed using
yaml.safe_loadand strictly validated against Pydantic models withextra="forbid"settings, preventing unexpected behavior or malicious object construction.
Audit Metadata