canvas-component-utils
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The instructions for rendering external HTML via the
FormattedTextcomponent define an indirect prompt injection surface. - Ingestion points: External HTML content is ingested via React props, as documented in
SKILL.md. - Boundary markers: None are present in the provided code examples.
- Capability inventory: The skill facilitates rendering rich text and images within a web application interface.
- Sanitization: The documentation does not specify sanitization procedures, relying on the underlying library implementation.
- [EXTERNAL_DOWNLOADS]: The skill references the
drupal-canvasand@drupal-canvas/headlesspackages, which are vendor-provided resources associated with the skill author.
Audit Metadata