with-canvas
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No evidence of instructions attempting to override agent behavior, bypass safety filters, or extract system prompts. The instructions are strictly focused on technical guidance for canvas development.
- [DATA_EXFILTRATION]: No patterns of sensitive data access (e.g., credentials, private keys) or unauthorized network communication were detected. The skill does not perform any network requests.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns, such as piping downloads to a shell or dynamic script execution, are present. The skill references well-known libraries (Three.js, p5.js, Konva) but does not include malicious installation scripts.
- [OBFUSCATION]: No obfuscated strings, hidden Unicode characters, or encoded payloads were found in any of the files.
- [COMMAND_EXECUTION]: The skill does not contain any shell commands or subprocess calls. All instructions are informational and directed toward the agent's reasoning process.
- [NO_CODE]: The skill contains no executable code or script files; it is composed entirely of Markdown documentation and configuration metadata.
Audit Metadata