transform-image

Warn

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill generates Python scripts using string interpolation of user-supplied variables like {source_path} and {output_dir}. These scripts are then executed using uv run. This creates a vulnerability where a user could provide a path containing Python code (e.g., using quotes and semicolons) to escape the intended string literal and execute arbitrary commands.
  • [REMOTE_CODE_EXECUTION]: The skill instructions direct the agent to generate and execute Python code at runtime using the Pillow and cairosvg libraries. This dynamic code generation pattern is highly capable and requires rigorous input validation to prevent execution of malicious code.
  • [DATA_EXFILTRATION]: The skill uses the cairosvg library to process SVG files, which supports fetching resources from external URLs via its API. If the svg_path is user-controlled and points to a remote resource, it could be used for unexpected network requests or data exfiltration.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes uv run with the --with flag to include Pillow and cairosvg. This triggers the download of these packages from official registries if they are not already present in the environment. These are well-known libraries used for their standard functionality.
  • [COMMAND_EXECUTION]: In the ingestion point of source_path and output_dir (SKILL.md), there are no boundary markers or instructions to sanitize inputs before interpolation into the Python script templates. The skill possesses capabilities for subprocess execution (uv run) and file system access, which are typical for its purpose but represent an attack surface for indirect prompt injection if processing untrusted file metadata.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 20, 2026, 04:21 PM
Security Audit — agent-trust-hub — transform-image