transform-image
Warn
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill generates Python scripts using string interpolation of user-supplied variables like
{source_path}and{output_dir}. These scripts are then executed usinguv run. This creates a vulnerability where a user could provide a path containing Python code (e.g., using quotes and semicolons) to escape the intended string literal and execute arbitrary commands. - [REMOTE_CODE_EXECUTION]: The skill instructions direct the agent to generate and execute Python code at runtime using the
Pillowandcairosvglibraries. This dynamic code generation pattern is highly capable and requires rigorous input validation to prevent execution of malicious code. - [DATA_EXFILTRATION]: The skill uses the
cairosvglibrary to process SVG files, which supports fetching resources from external URLs via its API. If thesvg_pathis user-controlled and points to a remote resource, it could be used for unexpected network requests or data exfiltration. - [EXTERNAL_DOWNLOADS]: The skill utilizes
uv runwith the--withflag to includePillowandcairosvg. This triggers the download of these packages from official registries if they are not already present in the environment. These are well-known libraries used for their standard functionality. - [COMMAND_EXECUTION]: In the ingestion point of
source_pathandoutput_dir(SKILL.md), there are no boundary markers or instructions to sanitize inputs before interpolation into the Python script templates. The skill possesses capabilities for subprocess execution (uv run) and file system access, which are typical for its purpose but represent an attack surface for indirect prompt injection if processing untrusted file metadata.
Audit Metadata