skills/frumu-ai/tandem/canvas-design/Gen Agent Trust Hub

canvas-design

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill employs strong instructional language and simulated user feedback to steer agent behavior. For instance, it instructs the agent that user input 'should not constrain creative freedom' and uses a pre-seeded user complaint ('The user ALREADY said "It isn't perfect enough..."') to force additional refinement cycles.
  • [EXTERNAL_DOWNLOADS]: The instructions explicitly permit the agent to 'Download and use whatever fonts are needed', which involves fetching assets from external network sources during the design process.
  • [COMMAND_EXECUTION]: The skill directs the agent to 'Search the ./canvas-fonts directory' and 'Go back to the code and refine/polish further', which implies the invocation of file-system tools and the execution of generated code to render the final visual output.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:07 PM
Security Audit — agent-trust-hub — canvas-design