canvas-component-definition

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill retrieves a validation schema from git.drupalcode.org, which is the official repository host for the Drupal project.
  • [COMMAND_EXECUTION]: It recommends using the ajv-cli tool via npx to perform validation on component mock files.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads external project files, creating a potential surface for indirect prompt injection. 1. Ingestion points: Reads configuration and source files including package.json, .env, index.jsx, and component.yml. 2. Boundary markers: None identified. 3. Capability inventory: Accesses local files and executes shell-based validation commands. 4. Sanitization: None identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 08:40 AM
Security Audit — agent-trust-hub — canvas-component-definition