with-canvas

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of instructions attempting to override agent behavior, bypass safety filters, or extract system prompts. The instructions are strictly focused on technical guidance for canvas development.
  • [DATA_EXFILTRATION]: No patterns of sensitive data access (e.g., credentials, private keys) or unauthorized network communication were detected. The skill does not perform any network requests.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns, such as piping downloads to a shell or dynamic script execution, are present. The skill references well-known libraries (Three.js, p5.js, Konva) but does not include malicious installation scripts.
  • [OBFUSCATION]: No obfuscated strings, hidden Unicode characters, or encoded payloads were found in any of the files.
  • [COMMAND_EXECUTION]: The skill does not contain any shell commands or subprocess calls. All instructions are informational and directed toward the agent's reasoning process.
  • [NO_CODE]: The skill contains no executable code or script files; it is composed entirely of Markdown documentation and configuration metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 06:19 AM
Security Audit — agent-trust-hub — with-canvas