canvas-design

Pass

Audited by Gen Agent Trust Hub on Jun 27, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's structure and instructions are entirely dedicated to creative design. The analyzed files, including markdown instructions and font license texts, contain no scripts, secrets, or network exfiltration logic.
  • [PROMPT_INJECTION]: The skill employs a context manipulation technique by instructing the agent that 'The user ALREADY said' the work needs to be a 'masterpiece.' This fabrication of past conversation is used to programmatically trigger a refinement and polishing stage in the agent's workflow. While this uses a behavioral override pattern, it is applied here for the benign purpose of enforcing artistic quality.
  • [EXTERNAL_DOWNLOADS]: There is a general instruction to 'Download and use whatever fonts are needed' to enhance the artistic output. This allows the agent to fetch creative assets but does not direct it toward malicious sources or untrusted repositories. The skill also provides a local directory of font information to guide the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 27, 2026, 11:03 AM
Security Audit — agent-trust-hub — canvas-design