canary-watch

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection through its monitoring of external web content.
  • Ingestion points: The agent fetches and processes content from external URLs, specifically targeting HTML elements, console error logs, and network response data.
  • Boundary markers: The instructions do not define boundary markers or clear directives to the agent to disregard any natural language instructions found within the ingested web data.
  • Capability inventory: The agent uses browser/network capabilities to access remote URLs, maintains a local log file (~/.claude/canary-watch.log), and has the ability to send status updates to external Slack or Discord webhooks.
  • Sanitization: There are no defined processes for the agent to sanitize, filter, or validate the content retrieved from the monitored URLs before it is incorporated into the session context.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 12:19 AM
Security Audit — agent-trust-hub — canary-watch