lov-png2svg
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using
magick,vtracer, andsvgoto process image files and perform vectorization. These commands are local operations necessary for the skill's primary function. - [EXTERNAL_DOWNLOADS]: The documentation references installation commands for dependencies using well-known package managers including Homebrew (
brew install imagemagick), Cargo (cargo install vtracer), and NPM (npm install -g svgo). These are standard development tools and do not involve untrusted remote sources. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided file paths (
INPUT_PNG) which are interpolated directly into shell command strings inSKILL.md. This represents a potential injection surface if the input paths are not properly sanitized by the agent's execution environment. - Ingestion points: The
INPUT_PNGvariable inSKILL.mdis an entry point for user-controlled data. - Boundary markers: None identified in the skill instructions.
- Capability inventory: The skill uses
magick,vtracer,npx svgo, andrm(documented inSKILL.md). - Sanitization: No explicit sanitization or validation of the input paths is provided within the skill's instruction set.
Audit Metadata