canvas-regions
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides instructions for managing site layout through regional JSON configuration files and React components, which is standard functionality for the drupal-canvas framework.
- [COMMAND_EXECUTION]: The instructions direct the agent to run
npx canvas validateto ensure authored files meet the required schema. This is a standard project-specific utility command. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local project files, such as
package.jsonandcanvas.config.json, to determine the project type and configuration directories. - Ingestion points: Reads
package.json(to check for@drupal-canvas/headlessdependencies) andcanvas.config.json(to locateregionsDirandlayoutPath) in SKILL.md. - Boundary markers: None; relies on standard file structure.
- Capability inventory: File system write operations (creating/modifying
.jsonand.jsxfiles) and command execution (npx canvas validate). - Sanitization: The skill defines strict JSON format constraints and naming conventions for authored content.
Audit Metadata