canvas-design

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill utilizes imperative language and pre-simulated user feedback ("The user ALREADY said 'It isn't perfect enough...' ") to override the agent's default conversational flow and force a specific "masterpiece" output quality.
  • [EXTERNAL_DOWNLOADS]: The instructions direct the agent to "Download and use whatever fonts are needed," which encourages fetching external assets from unspecified remote sources without integrity validation.
  • [PROMPT_INJECTION]: An indirect prompt injection attack surface was identified in the workflow for processing user inputs.
  • Ingestion points: User-supplied "subtle input" and "niche references" are used as the core conceptual DNA for generating visual content (SKILL.md).
  • Boundary markers: Absent. The skill does not provide delimiters or instructions to ignore potential commands embedded within user-provided references.
  • Capability inventory: The skill has the ability to generate and save multiple file formats, including .md, .pdf, and .png.
  • Sanitization: Absent. There are no mechanisms mentioned for validating or filtering the content of external references provided by the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 05:06 PM
Security Audit — agent-trust-hub — canvas-design