canvas-data-fetching
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute Node.js commands using the
node -eflag to probe API endpoints and inspect data shapes. This involves running dynamic module code directly in the shell. - [DYNAMIC_EXECUTION]: The suggested debugging probe uses dynamic
importstatements and runtime environment modification (globalThis.window = {}) to execute logic outside the standard application lifecycle. - [DATA_EXFILTRATION]: The skill guides the agent to read potentially sensitive configuration from
.envand~/.canvasrc(a hidden file in the user's home directory) to resolveCANVAS_SITE_URL. This access to home-directory configuration presents a risk of exposing local development credentials. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill ingests data from external Drupal JSON:API endpoints using the
JsonApiClientanduseSWRhooks inSKILL.md. - Boundary markers: None implemented for the API data itself, though the skill mandates a manual verification process for request results.
- Capability inventory: The skill performs network operations via
fetchandJsonApiClient, and local shell execution via the Node.js probe pattern. - Sanitization: The skill focuses on verifying field presence and structure but does not specify programmatic sanitization of the content retrieved from the Drupal API before it is rendered in React components.
Audit Metadata