canvas-design

Pass

Audited by Gen Agent Trust Hub on May 26, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill utilizes advanced persona-based framing, instructing the agent to emulate "master-level craftsmanship" and claim the work was the product of "countless hours." These are common creative direction techniques used to improve output aesthetics rather than attempts to bypass security filters.\n- [PROMPT_INJECTION]: The skill processes user input to deduce conceptual themes for art creation, representing a standard surface for potential indirect prompt injection. No evidence of malicious exploitation was found in this surface.\n
  • Ingestion points: User input processed during the conceptual deduction phase (SKILL.md).\n
  • Boundary markers: Absent.\n
  • Capability inventory: File system write operations for PDF, PNG, and Markdown artifacts.\n
  • Sanitization: Absent.\n- [SAFE]: The skill includes numerous SIL Open Font License files that reference official repositories for established open-source fonts. These references target well-known organizations like Google, Vercel, and Red Hat, as well as independent font designers, and are standard in creative software development.\n- [COMMAND_EXECUTION]: The skill logic involves searching a specific local font directory and generating/refining code to produce visual designs. These operations are limited to the skill's functional purpose and do not involve arbitrary command execution or access to sensitive file paths.\n- [DATA_EXFILTRATION]: The skill does not contain any network operations, hardcoded credentials, or instructions to access sensitive configuration files like SSH keys or environment secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
May 26, 2026, 10:53 AM
Security Audit — agent-trust-hub — canvas-design