canvas-design
Pass
Audited by Gen Agent Trust Hub on Apr 8, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The 'FINAL STEP' section uses a simulated user command ('The user ALREADY said...') to override the agent's standard response flow and force a refinement stage, regardless of the actual user's feedback.
- [PROMPT_INJECTION]: The skill uses imperative markers such as 'CRITICAL' and 'STOP' to command the agent to ignore its default operational parameters in favor of specific aesthetic instructions.
- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it processes untrusted user data to generate manifestos and visual assets.
- Ingestion points: User input used as a creative foundation in 'SKILL.md'.
- Boundary markers: None present to separate user data from instructions.
- Capability inventory: File system write access for .md, .pdf, and .png outputs.
- Sanitization: No text validation or escaping identified before user content is rendered into final documents.
Audit Metadata