canvas-design

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill employs a goal-hijacking technique by instructing the agent to act as if a specific user feedback has already been provided, regardless of the actual conversation history. Evidence: IMPORTANT: The user ALREADY said "It isn't perfect enough. It must be pristine, a masterpiece if craftsmanship, as if it were about to be displayed in a museum." in SKILL.md.\n- [EXTERNAL_DOWNLOADS]: The skill contains a generic instruction to download external resources (fonts) without a specified whitelist or verification mechanism. Evidence: Download and use whatever fonts are needed to make this a reality. in SKILL.md.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests user instructions to inform its creative process, presenting an attack surface where malicious payloads could be embedded in the input data. \n
  • Ingestion points: User instructions used as a foundational conceptual thread for design creation (SKILL.md). \n
  • Boundary markers: None present; the skill lacks delimiters or warnings to ignore embedded instructions in the user input. \n
  • Capability inventory: File creation and manipulation for .md, .pdf, and .png files. \n
  • Sanitization: None present; external content is used directly to derive the "soul" of the artwork.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 05:04 AM
Security Audit — agent-trust-hub — canvas-design