designing-canvas-art
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses a behavior-override technique by instructing the agent to act as if the user has already provided specific feedback ("The user ALREADY said 'It isn't perfect enough...' "), which is an attempt to force a specific output state and bypass default behavioral constraints.
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted user data to drive artistic creation without sufficient boundaries.
- Ingestion points: User-provided 'subtle input or instructions' are used as the foundation for the design (SKILL.md).
- Boundary markers: Absent; there are no delimiters or instructions to ignore embedded commands within the user data.
- Capability inventory: The skill possesses the ability to write files (.png, .pdf) and perform code execution for image generation ("Go back to the code and refine/polish further").
- Sanitization: Absent; user input is incorporated into the creative process and potentially into text labels without validation.
- [DYNAMIC_EXECUTION]: The skill explicitly instructs the agent to generate, execute, and iteratively refine code ("Go back to the code and refine/polish further") to produce visual outputs, which constitutes runtime script generation and execution.
- [EXTERNAL_DOWNLOADS]: The instructions encourage the agent to "Download and use whatever fonts are needed" at runtime, which promotes the fetching of external resources from unspecified internet sources.
Audit Metadata