canvas-design

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill's primary function is aesthetic content generation. A thorough review of the instructions and the accompanying 27 font license files revealed no malicious code, data exfiltration patterns, or credential harvesting.
  • [PROMPT_INJECTION]: The skill uses a conversation manipulation technique in which it primes the agent with simulated user feedback ("The user ALREADY said 'It isn't perfect enough...' "). This is used as a creative prompt to ensure the agent targets a high level of craftsmanship rather than to bypass safety guardrails or extract sensitive information.
  • [EXTERNAL_DOWNLOADS]: The instructions direct the agent to "Download and use whatever fonts are needed." This instruction is intended for fetching design assets to fulfill the skill's purpose. The provided license files reference reputable sources such as Google Fonts and Vercel's official repositories, and the skill also points to a local directory for asset management.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 03:18 AM
Security Audit — agent-trust-hub — canvas-design