canvas-regions

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides instructions for managing site layout through regional JSON configuration files and React components, which is standard functionality for the drupal-canvas framework.
  • [COMMAND_EXECUTION]: The instructions direct the agent to run npx canvas validate to ensure authored files meet the required schema. This is a standard project-specific utility command.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local project files, such as package.json and canvas.config.json, to determine the project type and configuration directories.
  • Ingestion points: Reads package.json (to check for @drupal-canvas/headless dependencies) and canvas.config.json (to locate regionsDir and layoutPath) in SKILL.md.
  • Boundary markers: None; relies on standard file structure.
  • Capability inventory: File system write operations (creating/modifying .json and .jsx files) and command execution (npx canvas validate).
  • Sanitization: The skill defines strict JSON format constraints and naming conventions for authored content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 12:47 PM
Security Audit — agent-trust-hub — canvas-regions