canvas-design

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, such as prompt injection, data exfiltration, or obfuscation, were found in the skill's files.
  • [COMMAND_EXECUTION]: The skill instructions and documentation mention the use of shell commands and internal Python scripts (e.g., ls ./canvas-fonts/, scripts/list-canvas-fonts.py). These are standard operational procedures for the skill to manage its own assets and do not involve untrusted input or elevated privileges.
  • [EXTERNAL_DOWNLOADS]: The skill does not perform any external network requests or remote code downloads. The URLs present in the repository are limited to official font licenses (SIL Open Font License) and established project repositories (e.g., GitHub), which are considered safe references.
  • [DATA_EXFILTRATION]: No patterns indicative of data harvesting or exfiltration were detected. File system access is scoped to the skill's own directories for fonts and scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 03:20 PM
Security Audit — agent-trust-hub — canvas-design