canvas-design
Pass
Audited by Gen Agent Trust Hub on May 26, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill utilizes advanced persona-based framing, instructing the agent to emulate "master-level craftsmanship" and claim the work was the product of "countless hours." These are common creative direction techniques used to improve output aesthetics rather than attempts to bypass security filters.\n- [PROMPT_INJECTION]: The skill processes user input to deduce conceptual themes for art creation, representing a standard surface for potential indirect prompt injection. No evidence of malicious exploitation was found in this surface.\n
- Ingestion points: User input processed during the conceptual deduction phase (SKILL.md).\n
- Boundary markers: Absent.\n
- Capability inventory: File system write operations for PDF, PNG, and Markdown artifacts.\n
- Sanitization: Absent.\n- [SAFE]: The skill includes numerous SIL Open Font License files that reference official repositories for established open-source fonts. These references target well-known organizations like Google, Vercel, and Red Hat, as well as independent font designers, and are standard in creative software development.\n- [COMMAND_EXECUTION]: The skill logic involves searching a specific local font directory and generating/refining code to produce visual designs. These operations are limited to the skill's functional purpose and do not involve arbitrary command execution or access to sensitive file paths.\n- [DATA_EXFILTRATION]: The skill does not contain any network operations, hardcoded credentials, or instructions to access sensitive configuration files like SSH keys or environment secrets.
Audit Metadata