canva-image-editor

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to run locally hosted Python scripts (e.g., auth_check.py, update_text.py) for Canva API operations. This is a functional requirement for the skill's purpose.
  • [PROMPT_INJECTION]: By reading and processing text content from external Canva designs, the skill presents an indirect prompt injection surface. This risk is effectively mitigated by the mandatory 'CLARIFY' workflow stage, which requires the agent to obtain explicit user confirmation before implementing any changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 12:43 AM
Security Audit — agent-trust-hub — canva-image-editor