kmp-imagevector-generator
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/convert_image_to_imagevector.pyusessubprocess.runto invoke thepotracecommand-line utility for monochrome image tracing. This is a standard operation within the asset pipeline and uses controlled arguments without a shell context. - [EXTERNAL_DOWNLOADS]: The skill documentation includes examples for fetching remote SVG icons from the
tailwindlabs/heroiconsrepository on GitHub. This organization is a well-known provider of design assets, and the fetches are restricted to specific, trusted resource paths. - [INDIRECT_PROMPT_INJECTION]: The skill processes external SVG and raster data, which represents a theoretical attack surface for indirect prompt injection.
- Ingestion points: SVG and raster files processed by
scripts/convert_image_to_imagevector.py. - Boundary markers: The script uses regular expressions to extract specific attributes and validates the input entropy to reject non-iconographic content.
- Capability inventory: The skill can perform file writes to generate Kotlin source code and execute local binaries for image tracing.
- Sanitization: Input data is sanitized through quantization and normalization processes, and the script enforces a strict node budget (
--max-nodes) to prevent resource exhaustion or bloated outputs.
Audit Metadata