canvas-design

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses behavioral steering by providing instructions that simulate prior user feedback to mandate a specific quality level and iterative refinement process.- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The instructions direct the agent to "Download and use whatever fonts are needed," which involves fetching assets from external network locations to fulfill design requirements.- [DYNAMIC_EXECUTION]: The instruction to "Go back to the code and refine/polish" implies a workflow involving the generation and execution of scripts to produce the requested design artifacts.- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided conceptual foundation as the DNA for visual forms, creating an ingestion point for untrusted data that is then handled by the agent's file-generation and code-execution capabilities.
  • Ingestion points: Conceptual threads deduced from user requests (SKILL.md).
  • Boundary markers: Absent.
  • Capability inventory: File-writing (.pdf, .png, .md), code refinement and execution.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 08:03 PM
Security Audit — agent-trust-hub — canvas-design