canvas-design
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The 'FINAL STEP' section uses a behavioral override technique by pre-emptively stating that the user was unhappy with the output ('The user ALREADY said "It isn't perfect enough..."'), forcing the agent into a refinement loop regardless of actual user feedback.- [PROMPT_INJECTION]: The instructions command the agent to treat user input as a 'foundation' that 'should not constrain creative freedom,' directing the agent to bypass user-defined constraints during the creative process.- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to 'Download and use whatever fonts are needed,' which involves network operations to fetch external assets from arbitrary sources at runtime.- [SAFE]: The skill provides an attack surface for indirect prompt injection as it processes user input to generate designs (Ingestion points: SKILL.md), lacks explicit instruction boundary markers or 'ignore' warnings for processed data (Boundaries), and has capabilities to write files and access the network (Capabilities: file write, font download) without visible evidence of input sanitization (Sanitization).
Audit Metadata