canvas-workspace

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed to manage local canvas files (.excalidraw) and assets within the project's prototype directories. All identified operations are consistent with its stated purpose.
  • [COMMAND_EXECUTION]: The skill references the axhub-make CLI tool for operations such as annotations, info, screenshot, and refresh. These commands are used to interact with the local development environment and do not involve arbitrary shell execution or unsafe user input processing.
  • [EXTERNAL_DOWNLOADS]: A reference to a diagramming guide on skills.sh is provided for user education. This is a well-known community platform for AI agent skills and the link is presented transparently.
  • [DATA_EXFILTRATION]: No network exfiltration patterns were detected. The skill interacts with local development servers (localhost) and project-specific APIs, which is standard for prototyping tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 10:22 AM
Security Audit — agent-trust-hub — canvas-workspace