canva-translate-design

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to ingest and translate text elements from external Canva designs. Because this content comes from an external source, it could potentially contain embedded instructions intended to influence the agent's behavior during the translation process.
  • Ingestion points: The workflow in SKILL.md involves gathering all text elements from a source Canva design in step 3.
  • Boundary markers: The instructions do not specify the use of clear delimiters or instructions to treat the gathered text as data rather than instructions.
  • Capability inventory: The skill possesses the ability to search for, duplicate, and modify design elements in the user's Canva account.
  • Sanitization: There are no explicit steps for sanitizing or validating the text content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 11:58 AM
Security Audit — agent-trust-hub — canva-translate-design