canvas-component-metadata

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using npx canvas agents-context to synchronize metadata and preview property shapes. These commands are associated with the vendor's own tooling for component development.
  • [EXTERNAL_DOWNLOADS]: The documentation includes example asset URLs from well-known services such as Unsplash (images.unsplash.com) and iStockphoto (media.istockphoto.com) to demonstrate how image and video metadata should be structured.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies an attack surface where the agent processes local project files and remote data, which could potentially contain malicious instructions.
  • Ingestion points: Reads local component.yml, package.json, and component source files (React, Astro, or Vue). It also ingests data from a configured Canvas site using CLI tools.
  • Boundary markers: Absent. The instructions do not specify any delimiters or warnings to ignore instructions embedded within the processed data or files.
  • Capability inventory: The skill utilizes file system access for reading and writing project metadata and source code, as well as shell command execution.
  • Sanitization: No explicit sanitization or validation steps are provided for the content of entity fields or metadata example values.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:26 PM
Security Audit — agent-trust-hub — canvas-component-metadata