canvas-workbench

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and run the @drupal-canvas/workbench package using package runners like npx, pnpm dlx, bunx, or yarn dlx if it is not already installed in the local environment. These packages are within the vendor's own namespace.
  • [COMMAND_EXECUTION]: The skill executes shell commands to start a local development server for component and page verification. It also suggests commands for installing the workbench tool as a dev dependency.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local project files to determine behavior and configuration.
  • Ingestion points: Reads package.json for dependencies, canvas.config.json for path configuration, and component-related files (component.yml, mocks.json, and page JSON files) for previewing content.
  • Boundary markers: None explicitly defined for these configuration files.
  • Capability inventory: The agent can execute shell commands via package managers and write or update the canvas.config.json file.
  • Sanitization: No specific sanitization or validation logic is detailed for the contents of these project files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 12:47 PM
Security Audit — agent-trust-hub — canvas-workbench