canvas-widget

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local shell scripts (tq, new-canvas) to interact with the tldraw application's local API via curl and manage canvas files on the local filesystem.\n- [EXTERNAL_DOWNLOADS]: Instructions guide the agent to research and port code logic from established technical documentation and reference sites such as tldraw.dev, MDN, and D3 gallery.\n- [REMOTE_CODE_EXECUTION]: The skill implementing persistent widget behavior by writing JavaScript code into the tldraw application's internal script workspace, which is then executed by the application to provide interactivity.\n- [CREDENTIALS_UNSAFE]: To authenticate with the local tldraw server, the skill reads an ephemeral bearer token from the application's local configuration file (server.json). This access is localized and essential for the tool's core functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 05:42 PM
Security Audit — agent-trust-hub — canvas-widget