json-canvas
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines workflows for reading, parsing, and modifying
.canvasfiles which contain user-controlled data fields. - Ingestion points: Workflows in
SKILL.md(e.g., "Add a Node to an Existing Canvas", "Edit an Existing Canvas") instruct the agent to read and parse external JSON files. - Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following malicious commands that might be embedded in the
text,label, orurlfields of the JSON objects. - Capability inventory: The skill empowers the agent to perform file system read and write operations on
.canvasfiles and follow externalurllinks defined in nodes. - Sanitization: The skill lacks instructions for sanitizing or escaping the content of text nodes (which support Markdown) before the agent processes them, creating a surface for potential prompt injection.
Audit Metadata