canvas-setup
Pass
Audited by Gen Agent Trust Hub on Jul 26, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses local shell scripts (
scripts/tqandscripts/new-canvas) to automate file management and interact with the local tldraw application bridge viacurl. These operations are standard for the skill's intended functionality. - [DATA_EXFILTRATION]: The skill accesses local application configuration files (e.g.,
server.json) to retrieve a transient authentication token used for communicating with the localtldraw offlinedesktop app vialocalhost. No sensitive system credentials or external network exfiltration patterns were found. - [PROMPT_INJECTION]: The skill suggests adding a preference to the agent's instruction file (e.g.,
CLAUDE.md) to prioritize the kit's canvas for visual tasks. This is presented as an optional configuration and requires explicit user consent.
Audit Metadata