lov-png2svg

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using magick, vtracer, and svgo to process image files and perform vectorization. These commands are local operations necessary for the skill's primary function.
  • [EXTERNAL_DOWNLOADS]: The documentation references installation commands for dependencies using well-known package managers including Homebrew (brew install imagemagick), Cargo (cargo install vtracer), and NPM (npm install -g svgo). These are standard development tools and do not involve untrusted remote sources.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided file paths (INPUT_PNG) which are interpolated directly into shell command strings in SKILL.md. This represents a potential injection surface if the input paths are not properly sanitized by the agent's execution environment.
  • Ingestion points: The INPUT_PNG variable in SKILL.md is an entry point for user-controlled data.
  • Boundary markers: None identified in the skill instructions.
  • Capability inventory: The skill uses magick, vtracer, npx svgo, and rm (documented in SKILL.md).
  • Sanitization: No explicit sanitization or validation of the input paths is provided within the skill's instruction set.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 03:44 PM
Security Audit — agent-trust-hub — lov-png2svg