json-canvas
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to ingest and parse .canvas files, which contain arbitrary user-defined text and metadata.\n- Ingestion points: Workflows in SKILL.md require reading and parsing existing .canvas files from the filesystem during creation and editing tasks.\n- Boundary markers: The skill lacks explicit instructions or delimiters to prevent the agent from interpreting markdown text within 'text' nodes as commands.\n- Capability inventory: The agent is authorized to read and write files and handle external URLs through the 'file' and 'url' node types, creating a potential exploitation chain.\n- Sanitization: No sanitization or content filtering is specified for the values provided in node attributes.
Audit Metadata