kmp-imagevector-generator

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/convert_image_to_imagevector.py uses subprocess.run to invoke the potrace command-line utility for monochrome image tracing. This is a standard operation within the asset pipeline and uses controlled arguments without a shell context.
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes examples for fetching remote SVG icons from the tailwindlabs/heroicons repository on GitHub. This organization is a well-known provider of design assets, and the fetches are restricted to specific, trusted resource paths.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external SVG and raster data, which represents a theoretical attack surface for indirect prompt injection.
  • Ingestion points: SVG and raster files processed by scripts/convert_image_to_imagevector.py.
  • Boundary markers: The script uses regular expressions to extract specific attributes and validates the input entropy to reject non-iconographic content.
  • Capability inventory: The skill can perform file writes to generate Kotlin source code and execute local binaries for image tracing.
  • Sanitization: Input data is sanitized through quantization and normalization processes, and the script enforces a strict node budget (--max-nodes) to prevent resource exhaustion or bloated outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:35 PM
Security Audit — agent-trust-hub — kmp-imagevector-generator