canvas-design

Warn

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill utilizes a simulated user input override in the 'FINAL STEP' section. By instructing the agent to act as if the user 'ALREADY said' specific phrases, it forces a predetermined behavioral state that ignores actual user intent and current session context.
  • [EXTERNAL_DOWNLOADS]: The agent is commanded to 'Download and use whatever fonts are needed', promoting the retrieval of unverified binary files from the open internet, which presents tracking and supply chain risks.
  • [PROMPT_INJECTION]: The skill exhibits vulnerability to indirect prompt injection through its ingestion of untrusted inputs. * Ingestion points: 'design-brief' and 'creative-direction' defined in SKILL.md. * Boundary markers: None present to distinguish instructions from user data. * Capability inventory: Capabilities include writing .md, .pdf, and .png files to the local file system. * Sanitization: No sanitization or filtering of external creative directions is implemented.
  • [COMMAND_EXECUTION]: The 'FINAL STEP' directs the agent to 'Go back to the code and refine/polish', which involves the dynamic execution of locally generated scripts to produce visual artifacts.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 03:27 AM
Security Audit — agent-trust-hub — canvas-design