png-svg-converter

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run in scripts/convert.py to execute system binaries (magick, potrace, identify). This is a necessary part of the skill's primary purpose. The arguments are passed as a list rather than a shell string, which significantly reduces the risk of command injection.
  • [EXTERNAL_DOWNLOADS]: The skill requires several Linux binaries (magick, potrace, identify) to be pre-installed on the host system. It does not attempt to download or install these itself, only verifying their existence using shutil.which.
  • [DATA_EXPOSURE]: The skill creates temporary files in the system's temp directory using tempfile.TemporaryDirectory. This is a safe way to handle intermediate files during the conversion process.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — png-svg-converter