canvas-page-definition

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for processing local JSON page specifications which contain component properties and metadata. These files represent an ingestion surface for untrusted data if modified by external actors before the agent performs review or refactoring tasks.
  • Ingestion points: Local JSON files located in the project's pagesDir (default ./pages).
  • Boundary markers: None specified for user-controlled property values.
  • Capability inventory: File system read/write access and execution of npx canvas CLI utilities.
  • Sanitization: The skill mandates strict structural JSON validation and component-type verification using vendor tools.
  • [COMMAND_EXECUTION]: The skill directs the agent to use npx canvas validate and npx canvas agents-context cer-preview to ensure page specifications meet the project's contract. These are standard developer tools belonging to the @drupal-canvas vendor ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:12 PM
Security Audit — agent-trust-hub — canvas-page-definition