canvas-component-metadata
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using
npx canvas agents-contextto synchronize metadata and preview property shapes. These commands are associated with the vendor's own tooling for component development. - [EXTERNAL_DOWNLOADS]: The documentation includes example asset URLs from well-known services such as Unsplash (
images.unsplash.com) and iStockphoto (media.istockphoto.com) to demonstrate how image and video metadata should be structured. - [INDIRECT_PROMPT_INJECTION]: The skill identifies an attack surface where the agent processes local project files and remote data, which could potentially contain malicious instructions.
- Ingestion points: Reads local
component.yml,package.json, and component source files (React, Astro, or Vue). It also ingests data from a configured Canvas site using CLI tools. - Boundary markers: Absent. The instructions do not specify any delimiters or warnings to ignore instructions embedded within the processed data or files.
- Capability inventory: The skill utilizes file system access for reading and writing project metadata and source code, as well as shell command execution.
- Sanitization: No explicit sanitization or validation steps are provided for the content of entity fields or metadata example values.
Audit Metadata