canvas-headless
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes an architecture for processing external data.
- Ingestion points: External data enters the application via
fetchPage()andgetClient()SDK calls. - Boundary markers: The skill contains explicit instructions that
FormattedTextrequires trusted or sanitized HTML. - Capability inventory: The frontend app renders data using framework-native HTML injection primitives like
dangerouslySetInnerHTML,v-html, andset:html. - Sanitization: Guidance is provided to ensure that HTML injection is performed only on sanitized or trusted content.
- [DYNAMIC_EXECUTION]: The SDK includes a mechanism to automatically generate component registry modules within the
.canvas/directory during the build process. - [EXTERNAL_DOWNLOADS]: References official vendor packages under the
@drupal-canvasscope, which are used for standard SDK functionality and implementation.
Audit Metadata