skills/hk-hub/agentskills/json-canvas/Gen Agent Trust Hub

json-canvas

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to read and parse external .canvas files, which can contain user-controlled markdown text that may serve as a vector for indirect prompt injection.
  • Ingestion points: Workflow instructions in SKILL.md (e.g., "Read and parse the existing .canvas file") require the agent to ingest content from local files.
  • Boundary markers: There are no instructions or delimiters provided to the agent to distinguish between its system instructions and the content within the canvas file.
  • Capability inventory: The agent has the capability to read and write files on the local filesystem, as specified in the canvas editing workflows.
  • Sanitization: The validation checklist focuses on JSON integrity and schema compliance but lacks measures to sanitize or escape instructions embedded within the text nodes.
  • [DATA_EXFILTRATION]: The skill handles file nodes that store paths to local files, which could lead to unauthorized data exposure if a malicious canvas file is processed.
  • Evidence: SKILL.md defines a file attribute for nodes described as a "Path to file within the system."
  • Risk: If an attacker provides a .canvas file referencing sensitive local files (e.g., configuration or credential files), an agent following the instructions to "Locate the target node" or "Modify the desired attributes" might inadvertently access or expose sensitive data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — json-canvas