svg-inline

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The instructions involve the use of standard command-line tools such as npx svgo and wc -c to optimize SVG markup and verify file size reductions in a development environment.\n- [EXTERNAL_DOWNLOADS]: The skill references the execution of the svgo package from the npm registry via npx, which is a standard and well-known service for frontend tooling.\n- [PROMPT_INJECTION]: The skill is designed to scan user-provided code (HTML, React, Vue components), which creates a surface for indirect prompt injection.\n
  • Ingestion points: Source code files identified for audit in SKILL.md and references/rule.md.\n
  • Boundary markers: No specific delimiters or instructions to ignore embedded content are defined.\n
  • Capability inventory: The agent is instructed to perform file system reads and execute shell commands (npx, wc).\n
  • Sanitization: No specific sanitization or validation of the processed code files is described before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 12:52 PM
Security Audit — agent-trust-hub — svg-inline