canvas-design
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill employs a goal-hijacking technique by instructing the agent to act as if a specific user feedback has already been provided, regardless of the actual conversation history. Evidence:
IMPORTANT: The user ALREADY said "It isn't perfect enough. It must be pristine, a masterpiece if craftsmanship, as if it were about to be displayed in a museum."inSKILL.md.\n- [EXTERNAL_DOWNLOADS]: The skill contains a generic instruction to download external resources (fonts) without a specified whitelist or verification mechanism. Evidence:Download and use whatever fonts are needed to make this a reality.inSKILL.md.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests user instructions to inform its creative process, presenting an attack surface where malicious payloads could be embedded in the input data. \n - Ingestion points: User instructions used as a foundational conceptual thread for design creation (SKILL.md). \n
- Boundary markers: None present; the skill lacks delimiters or warnings to ignore embedded instructions in the user input. \n
- Capability inventory: File creation and manipulation for
.md,.pdf, and.pngfiles. \n - Sanitization: None present; external content is used directly to derive the "soul" of the artwork.
Audit Metadata