canvas-design
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill utilizes imperative language and pre-simulated user feedback ("The user ALREADY said 'It isn't perfect enough...' ") to override the agent's default conversational flow and force a specific "masterpiece" output quality.
- [EXTERNAL_DOWNLOADS]: The instructions direct the agent to "Download and use whatever fonts are needed," which encourages fetching external assets from unspecified remote sources without integrity validation.
- [PROMPT_INJECTION]: An indirect prompt injection attack surface was identified in the workflow for processing user inputs.
- Ingestion points: User-supplied "subtle input" and "niche references" are used as the core conceptual DNA for generating visual content (SKILL.md).
- Boundary markers: Absent. The skill does not provide delimiters or instructions to ignore potential commands embedded within user-provided references.
- Capability inventory: The skill has the ability to generate and save multiple file formats, including .md, .pdf, and .png.
- Sanitization: Absent. There are no mechanisms mentioned for validating or filtering the content of external references provided by the user.
Audit Metadata