canvas-design
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The FINAL STEP section in SKILL.md employs a context-manipulation technique by stating: The user ALREADY said It isn't perfect enough.... This attempts to override the agent's current state and force it into a refinement loop by fabricating a historical user interaction.
- [EXTERNAL_DOWNLOADS]: In the CANVAS CREATION section of SKILL.md, the instructions tell the agent to Download and use whatever fonts are needed to make this a reality. This behavioral directive encourages fetching files from unverified external sources, which is a risk if the agent's environment lacks strict download controls.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface: 1. Ingestion points: User input described as subtle input or instructions in SKILL.md. 2. Boundary markers: None identified; user input is treated as a foundational element without delimiters. 3. Capability inventory: Capability to create .pdf, .png, and .md files via agent tools. 4. Sanitization: No instructions for sanitizing or escaping user-provided text before incorporating it into the visual philosophy or artwork.
- [SAFE]: The skill includes a comprehensive set of SIL Open Font Licenses for locally referenced fonts in the canvas-fonts/ directory, which is a standard and safe practice for design-related skills.
Audit Metadata