canvas-extension-api

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill involves executing standard developer commands, such as npm install, node --test, and node scripts/validate-extension.mjs. These are intended for building, testing, and validating application packages and are restricted to the local workspace environment.
  • [EXTERNAL_DOWNLOADS]: The skill references official OpenHands repositories on GitHub for the TypeScript SDK and documentation. These are trusted, well-known sources associated with the skill's author, used for obtaining necessary development tools and reference materials.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an architecture for building applications that process user and server data. While this creates a potential surface for indirect prompt injection, the skill mitigates this by providing explicit security guidelines, such as using DOM APIs for safe text rendering and implementing strict input validation in the backend Sidecar pattern.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:36 PM
Security Audit — agent-trust-hub — canvas-extension-api