canvas-setup

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses local shell scripts (scripts/tq and scripts/new-canvas) to automate file management and interact with the local tldraw application bridge via curl. These operations are standard for the skill's intended functionality.
  • [DATA_EXFILTRATION]: The skill accesses local application configuration files (e.g., server.json) to retrieve a transient authentication token used for communicating with the local tldraw offline desktop app via localhost. No sensitive system credentials or external network exfiltration patterns were found.
  • [PROMPT_INJECTION]: The skill suggests adding a preference to the agent's instruction file (e.g., CLAUDE.md) to prioritize the kit's canvas for visual tasks. This is presented as an optional configuration and requires explicit user consent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 05:42 PM
Security Audit — agent-trust-hub — canvas-setup