canva-automation

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection via the brand template autofill feature.\n
  • Ingestion points: The data parameter in the CANVA_INITIATE_CANVA_DESIGN_AUTOFILL_JOB tool, which accepts a key-value mapping for template placeholders.\n
  • Boundary markers: The instructions do not define delimiters or specific warnings to the model to ignore potential instructions embedded within the provided data.\n
  • Capability inventory: The skill has the ability to create new designs, move items between folders, and export designs to various formats including PDF and MP4.\n
  • Sanitization: No explicit validation or sanitization process is described for the input data before it is sent to the Canva API.\n- [EXTERNAL_DOWNLOADS]: The skill involves communication with external network resources to function.\n
  • The setup section requires the user to add the vendor's MCP server at https://rube.app/mcp to their client configuration.\n
  • The CANVA_CREATE_ASSET_UPLOAD_JOB tool allows the agent to fetch media assets from arbitrary public URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 04:47 AM
Security Audit — agent-trust-hub — canva-automation