infopath-to-canvas

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • Command Execution: The skill utilizes system utilities such as expand.exe on Windows and cabextract on Linux/macOS to process InfoPath .xsn archive files. These operations are necessary for the migration process and use quoted paths to help manage input safely.
  • Indirect Prompt Injection Surface: During the inventory phase, the skill processes XML, XSD, and XSF files extracted from the user's form. This creates a potential surface where content within the form data could influence the behavior of the analysis agent or the subsequent generation of the Canvas app. This is a consideration when processing files from untrusted or unknown sources.
  • Tool Usage and Capabilities: The skill uses internal tools to interact with SharePoint schemas when requested by the user. These capabilities are used to ensure field compatibility between the original form and the new data source, which is part of the intended migration workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 05:39 AM
Security Audit — agent-trust-hub — infopath-to-canvas