agent-canvas-environment
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands like
curlandjqto interact with a local backend API athttp://localhost:8001. These commands are used for legitimate environment management tasks such as searching and creating conversations. - [DATA_EXFILTRATION]: The skill includes instructions to read a session API key from a specific local configuration file at
$HOME/.openhands/agent-canvas/api-key.txt. This access is part of the skill's primary purpose for authenticating with the local Agent Canvas service. The instructions emphasize secure handling by advising against printing the key and using encrypted headers (X-Expose-Secrets: encrypted) for credential forwarding. - [PROMPT_INJECTION]: The skill provides a mechanism for delegating tasks to new agent conversations using user-provided prompts. While this introduces an interface for indirect prompt injection, it is a standard functional component of the delegation feature and is mitigated by the guidance to use self-contained, task-specific prompts.
Audit Metadata