positron-abstract-svg

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill mentions fetching static SVG icons from the Seti UI repository on GitHub (github.com/jesseweed/seti-ui) when required icons are not found in the local environment. This is a reference to a well-known service for retrieving public design assets and does not involve executable code.
  • [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface because it processes untrusted data provided by the user to inform its SVG generation tasks.
  • Ingestion points: User-provided screenshots of the Positron UI and text-based icon names as specified in the gathering input section of SKILL.md.
  • Boundary markers: Not present for the ingested screenshots or names.
  • Capability inventory: File writing operations to save generated SVG images to the local repository as described in the workflow in SKILL.md.
  • Sanitization: The instructions include a step to manually strip platform-specific or renderer-injected attributes from the SVG code before final saving to ensure clean and safe output.
  • [SAFE]: The skill is focused on static image generation and follows established design practices. Analysis of the instructions and reference patterns reveals no evidence of code obfuscation, credential harvesting, or unauthorized system access.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 01:46 PM
Security Audit — agent-trust-hub — positron-abstract-svg