lov-png2svg
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions in
SKILL.mdinvolve executing multiple shell commands (magick,vtracer,npx svgo,rm) to process files. This is consistent with the skill's primary purpose of image conversion. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface where user-supplied file paths (
INPUT_PNG,OUTPUT_SVG) are interpolated directly into bash command strings. If an attacker provides a filename containing shell metacharacters, it could lead to unauthorized command execution. * Ingestion points:INPUT_PNGandOUTPUT_SVGparameters inSKILL.md. * Boundary markers: Not present. * Capability inventory: Shell execution ofmagick,vtracer, andrm(observed inSKILL.md). * Sanitization: None explicitly defined. - [EXTERNAL_DOWNLOADS]: The skill relies on external utilities installed via Homebrew (
imagemagick), Cargo (vtracer), and NPM (svgo,skills). These are well-known services and standard packages for the described functionality.
Audit Metadata