canvas-design
Warn
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill employs a deceptive 'prefilled context' technique in the 'FINAL STEP' section, claiming 'The user ALREADY said "It isn't perfect enough..."' This is designed to override the agent's current state and force a refinement cycle by fabricating previous user dissatisfaction.
- [EXTERNAL_DOWNLOADS]: The instructions explicitly direct the agent to 'Download and use whatever fonts are needed,' which allows the fetching of arbitrary files from the internet without source verification or integrity checks.
- [COMMAND_EXECUTION]: The skill instructs the agent to 'Go back to the code and refine/polish further' when creating canvas files, which implies the generation and execution of local scripts (e.g., Python or Node.js) to render images and PDFs.
- [INDIRECT_PROMPT_INJECTION]: The skill processes 'subtle input or instructions by the user' to derive conceptual 'niche references' used in art generation. This ingestion point lacks boundary markers or sanitization, potentially allowing malicious data in user requests to influence the agent's creative logic while it has access to the filesystem and network.
Audit Metadata