svg

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of documentation and code examples for software development using well-known libraries such as react-native-svg and react-native-svg-transformer. All external links point to official documentation, design tools (Figma, Noun Project), or standard optimization utilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes methods for rendering content from external sources via SvgUri and SvgXml. While this creates an ingestion surface for external data, the scope is limited to SVG rendering within the application environment and does not involve executing shell commands or accessing sensitive agent state. As such, the risk is minimal and consistent with standard development practices.
  • [COMMAND_EXECUTION]: The skill includes standard package management commands (npx expo install, yarn add) and Metro bundler configuration required for integrating SVG support into a React Native project. These are legitimate development operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 03:24 PM
Security Audit — agent-trust-hub — svg