canvas-design

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill includes instructions that manipulate the agent's context by pre-emptively simulating user feedback. Specifically, the 'FINAL STEP' section instructs the agent to act as if the user has already requested a more 'pristine' masterpiece, forcing a refinement iteration regardless of the actual user's intent.
  • [EXTERNAL_DOWNLOADS]: The instructions direct the agent to 'Download and use whatever fonts are needed', which promotes the retrieval of resources from external sources. While the provided font licenses point to legitimate repositories, the open-ended nature of the instruction is a potential security surface.
  • [SAFE]: The repository contains 27 standard SIL Open Font License files for established typography projects (e.g., Google Fonts, Vercel, IBM), confirming the skill's focus on legitimate visual design tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 10:25 PM
Security Audit — agent-trust-hub — canvas-design