canvas-navigation-components

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions align with standard development practices for the Drupal Canvas environment. It references authorized vendor resources such as @drupal-canvas/headless and uses official clients like JsonApiClient for data operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves ingesting data from external Drupal API sources (menu items and breadcrumbs). It handles this surface safely by recommending structured data fetching via SWR and providing mandatory fallback link constants to ensure UI stability regardless of the external data state.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 12:47 PM
Security Audit — agent-trust-hub — canvas-navigation-components