canvas-design

Pass

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The 'FINAL STEP' section uses a simulated user command ('The user ALREADY said...') to override the agent's standard response flow and force a refinement stage, regardless of the actual user's feedback.
  • [PROMPT_INJECTION]: The skill uses imperative markers such as 'CRITICAL' and 'STOP' to command the agent to ignore its default operational parameters in favor of specific aesthetic instructions.
  • [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it processes untrusted user data to generate manifestos and visual assets.
  • Ingestion points: User input used as a creative foundation in 'SKILL.md'.
  • Boundary markers: None present to separate user data from instructions.
  • Capability inventory: File system write access for .md, .pdf, and .png outputs.
  • Sanitization: No text validation or escaping identified before user content is rendered into final documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 8, 2026, 10:19 AM
Security Audit — agent-trust-hub — canvas-design