canvas-design
Pass
Audited by Gen Agent Trust Hub on Apr 13, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill uses a 'pre-injected context' technique to manipulate agent behavior. It explicitly claims that 'The user ALREADY said "It isn't perfect enough..."' to force the agent into a specific 'masterpiece' persona and override standard output guidelines.
- [EXTERNAL_DOWNLOADS]: The instructions include a directive to 'Download and use whatever fonts are needed to make this a reality.' This encourages the agent to perform network operations to fetch external assets from unknown sources.
- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection via user-supplied topics. Ingestion points: Subtle user input described in SKILL.md. Boundary markers: Absent. Capability inventory: File system writes (.md, .png, .pdf) in SKILL.md. Sanitization: Absent.
Audit Metadata