canvas-design
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests user conceptual foundations ('subtle input or instructions') to guide art creation. The absence of explicit boundary markers or input sanitization in the prompt creates a surface for indirect prompt injection (File: SKILL.md). Ingestion point: User conceptual foundations. Boundary markers: Absent. Capability inventory: Dynamic code generation and file-writing. Sanitization: Absent.
- [EXTERNAL_DOWNLOADS]: Instructions specify that the agent should 'Download and use whatever fonts are needed to make this a reality.' This presents an unconstrained download capability that could be exploited if malicious asset sources are provided at runtime (File: SKILL.md).
- [COMMAND_EXECUTION]: The skill workflow includes instructions to 'Go back to the code and refine/polish further,' which implies the dynamic generation and execution of rendering scripts (File: SKILL.md). This high-capability surface is central to the skill's function but requires monitoring and isolation.
Audit Metadata