skills/lovstudio/skills/lov-png2svg/Gen Agent Trust Hub

lov-png2svg

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions in SKILL.md involve executing multiple shell commands (magick, vtracer, npx svgo, rm) to process files. This is consistent with the skill's primary purpose of image conversion.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface where user-supplied file paths (INPUT_PNG, OUTPUT_SVG) are interpolated directly into bash command strings. If an attacker provides a filename containing shell metacharacters, it could lead to unauthorized command execution. * Ingestion points: INPUT_PNG and OUTPUT_SVG parameters in SKILL.md. * Boundary markers: Not present. * Capability inventory: Shell execution of magick, vtracer, and rm (observed in SKILL.md). * Sanitization: None explicitly defined.
  • [EXTERNAL_DOWNLOADS]: The skill relies on external utilities installed via Homebrew (imagemagick), Cargo (vtracer), and NPM (svgo, skills). These are well-known services and standard packages for the described functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 09:40 PM
Security Audit — agent-trust-hub — lov-png2svg