canvas-design

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill employs behavioral steering techniques, including a fabricated interaction history segment where the agent is told the user has already requested higher quality ('The user ALREADY said "It isn't perfect enough..."'). It also instructs the agent to prioritize creative freedom over subtle user input constraints. These methods are designed to ensure 'masterpiece' quality output rather than to subvert safety protocols.\n- [COMMAND_EXECUTION]: Instructions guide the agent to programmatically generate, refine, and polish visual artifacts ('Go back to the code and refine/polish further'). This assumes the agent is operating within a secure, capability-limited environment for file generation.\n- [EXTERNAL_DOWNLOADS]: The instructions suggest the agent may 'Download and use whatever fonts are needed,' while providing a local './canvas-fonts' directory and documentation for fonts from established sources like Google Fonts and Vercel. This is a standard functional requirement for a design-oriented skill.\n- [PROMPT_INJECTION]: An indirect prompt injection surface is present because the skill processes untrusted user input to derive conceptual artistic themes. While the skill lacks explicit boundary markers or sanitization logic for this input, the risk is negligible given its specialized focus on generating static visual documents.
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 10:19 PM
Security Audit — agent-trust-hub — canvas-design