canvas-design
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses behavioral steering by providing instructions that simulate prior user feedback to mandate a specific quality level and iterative refinement process.- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The instructions direct the agent to "Download and use whatever fonts are needed," which involves fetching assets from external network locations to fulfill design requirements.- [DYNAMIC_EXECUTION]: The instruction to "Go back to the code and refine/polish" implies a workflow involving the generation and execution of scripts to produce the requested design artifacts.- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided conceptual foundation as the DNA for visual forms, creating an ingestion point for untrusted data that is then handled by the agent's file-generation and code-execution capabilities.
- Ingestion points: Conceptual threads deduced from user requests (SKILL.md).
- Boundary markers: Absent.
- Capability inventory: File-writing (.pdf, .png, .md), code refinement and execution.
- Sanitization: Absent.
Audit Metadata