canvas-workbench
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and run the
@drupal-canvas/workbenchpackage using package runners like npx, pnpm dlx, bunx, or yarn dlx if it is not already installed in the local environment. These packages are within the vendor's own namespace. - [COMMAND_EXECUTION]: The skill executes shell commands to start a local development server for component and page verification. It also suggests commands for installing the workbench tool as a dev dependency.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local project files to determine behavior and configuration.
- Ingestion points: Reads
package.jsonfor dependencies,canvas.config.jsonfor path configuration, and component-related files (component.yml,mocks.json, and page JSON files) for previewing content. - Boundary markers: None explicitly defined for these configuration files.
- Capability inventory: The agent can execute shell commands via package managers and write or update the
canvas.config.jsonfile. - Sanitization: No specific sanitization or validation logic is detailed for the contents of these project files.
Audit Metadata