canvas-page-definition
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for processing local JSON page specifications which contain component properties and metadata. These files represent an ingestion surface for untrusted data if modified by external actors before the agent performs review or refactoring tasks.
- Ingestion points: Local JSON files located in the project's
pagesDir(default./pages). - Boundary markers: None specified for user-controlled property values.
- Capability inventory: File system read/write access and execution of
npx canvasCLI utilities. - Sanitization: The skill mandates strict structural JSON validation and component-type verification using vendor tools.
- [COMMAND_EXECUTION]: The skill directs the agent to use
npx canvas validateandnpx canvas agents-context cer-previewto ensure page specifications meet the project's contract. These are standard developer tools belonging to the@drupal-canvasvendor ecosystem.
Audit Metadata