canvas-design
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were identified. The skill's instructions are entirely focused on visual design and aesthetic movement creation.
- [PROMPT_INJECTION]: The skill does not contain instructions to override agent safety protocols or bypass system constraints. The instructions for 'human-crafted quality' are stylistic and do not attempt to deceive the user or bypass safety filters.
- [PROMPT_INJECTION]: Regarding Indirect Prompt Injection risk: The skill ingests user input to ground its design philosophies. While it lacks explicit boundary markers or sanitization, the risk is negligible given that the skill's capabilities are restricted to generating non-executable media files (.pdf, .png, .md).
- Ingestion points: User instructions mentioned in 'THE CRITICAL UNDERSTANDING' (SKILL.md).
- Boundary markers: Absent.
- Capability inventory: Generation of image and document files (PDF, PNG, Markdown).
- Sanitization: None specified for user-provided creative inputs.
- [DATA_EXFILTRATION]: No sensitive file paths (e.g., .ssh, .aws) or hardcoded credentials were found. The skill does not perform any network operations.
- [REMOTE_CODE_EXECUTION]: There is no evidence of external package installation or remote script execution via tools like curl or wget.
Audit Metadata