prototype-canvas

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs users to install the sp toolset directly from the vendor's official GitHub repository (github.com/ReScienceLab/super-prototyping) using the uv tool manager. It also notes that the tool fetches application components to a local cache folder (~/.cache/super-prototyping/) during its first run.
  • [DYNAMIC_EXECUTION]: The workflow relies on executing local Python scripts (gen.py) to generate or update artboard files within the project. It also utilizes a JavaScript bridge (window.snapCanvas) for programmatic interaction with the design canvas.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes HTML artboards from the local directory, creating a surface for potential indirect prompt injection. This is mitigated through several measures: 1. Ingestion points: Board folders containing .html files are indexed and rendered (SKILL.md). 2. Boundary markers: Artboards are rendered within sandboxed iframes (<iframe srcDoc sandbox="">) to prevent access to the main application context (references/layout.md). 3. Capability inventory: The skill executes local scripts and drives the canvas via a JS bridge, with optional AI agent integration (SKILL.md). 4. Sanitization: The documentation provides explicit safety rules against loading untrusted HTML and cautioning against enabling allow-same-origin on frames (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 03:56 PM
Security Audit — agent-trust-hub — prototype-canvas