canvas-component-definition
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill retrieves a validation schema from git.drupalcode.org, which is the official repository host for the Drupal project.
- [COMMAND_EXECUTION]: It recommends using the ajv-cli tool via npx to perform validation on component mock files.
- [INDIRECT_PROMPT_INJECTION]: The skill reads external project files, creating a potential surface for indirect prompt injection. 1. Ingestion points: Reads configuration and source files including package.json, .env, index.jsx, and component.yml. 2. Boundary markers: None identified. 3. Capability inventory: Accesses local files and executes shell-based validation commands. 4. Sanitization: None identified.
Audit Metadata