canvas-design
Warn
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill employs a narrative override technique in the 'FINAL STEP' section by asserting that the user has already provided specific negative feedback ('It isn't perfect enough...') to force the agent into a recursive refinement loop regardless of the actual user input.
- [EXTERNAL_DOWNLOADS]: The instructions direct the agent to 'Download and use whatever fonts are needed', which encourages the retrieval of external resources from unvalidated internet sources without providing specific trusted domains or integrity checks.
- [COMMAND_EXECUTION]: The skill requires the agent to generate and refine code to produce visual artifacts, instructing the agent to 'Go back to the code and refine/polish further'. This implies the use of local execution environments to run dynamically generated scripts for image or document creation.
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it processes untrusted user data to guide creative output while possessing powerful capabilities. * Ingestion points: User instructions are ingested as the conceptual foundation in
SKILL.md. * Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the user-provided input. * Capability inventory: The agent has the ability to write files, execute/refine code, and download external resources. * Sanitization: The skill lacks any mechanism to sanitize or validate the content of user input before it is used to guide the agent's actions.
Audit Metadata