canary-watch
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection through its monitoring of external web content.
- Ingestion points: The agent fetches and processes content from external URLs, specifically targeting HTML elements, console error logs, and network response data.
- Boundary markers: The instructions do not define boundary markers or clear directives to the agent to disregard any natural language instructions found within the ingested web data.
- Capability inventory: The agent uses browser/network capabilities to access remote URLs, maintains a local log file (~/.claude/canary-watch.log), and has the ability to send status updates to external Slack or Discord webhooks.
- Sanitization: There are no defined processes for the agent to sanitize, filter, or validate the content retrieved from the monitored URLs before it is incorporated into the session context.
Audit Metadata