agent-canvas-environment

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands like curl and jq to interact with a local backend API at http://localhost:8001. These commands are used for legitimate environment management tasks such as searching and creating conversations.
  • [DATA_EXFILTRATION]: The skill includes instructions to read a session API key from a specific local configuration file at $HOME/.openhands/agent-canvas/api-key.txt. This access is part of the skill's primary purpose for authenticating with the local Agent Canvas service. The instructions emphasize secure handling by advising against printing the key and using encrypted headers (X-Expose-Secrets: encrypted) for credential forwarding.
  • [PROMPT_INJECTION]: The skill provides a mechanism for delegating tasks to new agent conversations using user-provided prompts. While this introduces an interface for indirect prompt injection, it is a standard functional component of the delegation feature and is mitigated by the guidance to use self-contained, task-specific prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 12:07 PM
Security Audit — agent-trust-hub — agent-canvas-environment