canvas-design

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill uses a narrative technique to override the agent's perception of the user's satisfaction. By stating 'The user ALREADY said "It isn't perfect enough. It must be pristine..."', the skill attempts to force the agent into an obsessive refinement loop and a specific artistic persona, bypassing the agent's standard interaction flow.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided conceptual threads and 'subtle input' to influence the generation of design philosophies and visual art. This creates a surface where a user could provide instructions disguised as artistic concepts.
  • Ingestion points: User-provided 'subtle input or instructions' or 'conceptual thread' used as a foundation for the artwork.
  • Boundary markers: The instructions do not define clear delimiters or use 'ignore embedded instructions' warnings when processing the user's conceptual thread.
  • Capability inventory: The skill is instructed to output .md, .pdf, and .png files. It also searches a local directory for fonts.
  • Sanitization: There is no mention of sanitizing or validating the 'subtle input' provided by the user before incorporating it into the prompt logic for the 'Design Philosophy'.
  • [EXTERNAL_DOWNLOADS]: The skill explicitly instructs the agent to 'Download and use whatever fonts are needed to make this a reality' if the local options are insufficient. This encourages the agent to perform network requests and fetch assets from external sources, which could lead to the ingestion of untrusted files depending on the agent's toolset and search results.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 03:04 PM
Security Audit — agent-trust-hub — canvas-design