canvas-design

Warn

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill uses a simulated feedback technique in the FINAL STEP section where it instructs the agent to act as if the user already provided specific feedback (The user ALREADY said It isn't perfect enough...) to force a refinement cycle, bypassing the agent's natural interaction logic.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The CANVAS CREATION section directs the agent to Download and use whatever fonts are needed to make this a reality, which encourages the acquisition of external files from unverified third-party sources without specifying trusted origins or integrity verification mechanisms.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided conceptual inputs to generate visual artifacts, creating a potential attack surface for indirect instructions.
  • Ingestion points: User-provided foundation instructions (referenced in SKILL.md).
  • Boundary markers: Absent; the skill lacks instructions for the agent to distinguish between user-provided data and operational commands.
  • Capability inventory: Writing .pdf and .png files, searching local directories, and downloading external assets (referenced in SKILL.md).
  • Sanitization: Absent; user input is not escaped or validated before use in the design generation process.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — canvas-design