skills/jeremylongshore/tons-of-skills-marketplace/canva-advanced-troubleshooting/Gen Agent Trust Hub
canva-advanced-troubleshooting
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and classify diagnostic evidence and incident records from external sources, which acts as an attack surface for indirect prompt injection.
- Ingestion points: The skill's instructions and 'Support Escalation Template' describe processing 'redacted evidence,' 'incident records,' and 'response bodies' from API calls.
- Boundary markers: The skill does not define explicit delimiters or instructions to the agent to disregard potential commands embedded within the diagnostic data being analyzed.
- Capability inventory: The skill possesses network capabilities (using fetch and curl to communicate with api.canva.com) and file system access via the Read and Grep tools.
- Sanitization: While the skill advises manual redaction of telemetry, it lacks automated mechanisms to sanitize natural language instructions that might be present in the evidence logs.
Audit Metadata